Skip to content

Conversation

@fredrik0x
Copy link
Contributor

Description

As stated in the bug bounty program, the EF Bug Bounty Program bases its impact on the effect a vulnerability has on the Network: "The severity is calculated according to the OWASP risk rating model based on Impact on the Ethereum Network and Likelihood. View OWASP method"

Below the above line, there is an example of what could be described as a "High" vulnerability which states "There is a consensus bug between two clients, but it is difficult or impractical for the attacker to trigger the event." - This could indeed be accurate from a network perspective - if the issue was in a client being used by a large part of the network (say 45%), while if the consensus bug was in a client being used by 0.1% of the network it would most likely not have as big of an impact on the network itself.

This PR tries to make the example more clear.

Copy link
Contributor

@minimalsm minimalsm left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@minimalsm minimalsm merged commit 9a2d81c into dev Oct 24, 2022
@minimalsm minimalsm deleted the fredriksvantes-patch-2 branch October 24, 2022 11:54
@gitpoap-bot
Copy link

gitpoap-bot bot commented Oct 24, 2022

Congrats, your important contribution to this open-source project has earned you a GitPOAP!

GitPOAP: 2022 Ethereum.org Contributor:

GitPOAP: 2022 Ethereum.org Contributor GitPOAP Badge

Head to gitpoap.io & connect your GitHub account to mint!

Learn more about GitPOAPs here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants