Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9w7j-q3xw-p9vh

Опубликовано: 25 сент. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Hyperledger Fabric subject to Denial of Service via non-validated request

A vulnerability exists in Hyperledger Fabric < 2.4 could allow an attacker to construct a non-validated request that could cause a denial of service attack. The peer gateway service tries to extract channel and chaincode information from the signed proposal, but it doesn't check the proposal fields for validity. Therefore a malformed proposal might end up crashing the peer service. This issue has been patched in 2.4.6. There are no known workarounds.

Пакеты

Наименование

github.com/hyperledger/fabric

go
Затронутые версииВерсия исправления

< 2.4.6

2.4.6

7.5 High

CVSS3

Дефекты

CWE-20
CWE-400

Связанные уязвимости

nvd
больше 3 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.

7.5 High

CVSS3

Дефекты

CWE-20
CWE-400