Логотип exploitDog
bind:CVE-2022-31020
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-31020

Количество 2

Количество 2

nvd логотип

CVE-2022-31020

больше 3 лет назад

Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In versions 1.12.4 and prior, the `pool-upgrade` request handler in Indy-Node allows an improperly authenticated attacker to remotely execute code on nodes within the network. The `pool-upgrade` request handler in Indy-Node 1.12.5 has been updated to properly authenticate pool-upgrade transactions before any processing is performed by the request handler. The transactions are further sanitized to prevent remote code execution. As a workaround, endorsers should not create DIDs for untrusted users. A vulnerable ledger should configure `auth_rules` to prevent new DIDs from being written to the ledger until the network can be upgraded.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-r6v9-p59m-gj2p

больше 3 лет назад

Indy's NODE_UPGRADE transaction vulnerable to remote code execution

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-31020

Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In versions 1.12.4 and prior, the `pool-upgrade` request handler in Indy-Node allows an improperly authenticated attacker to remotely execute code on nodes within the network. The `pool-upgrade` request handler in Indy-Node 1.12.5 has been updated to properly authenticate pool-upgrade transactions before any processing is performed by the request handler. The transactions are further sanitized to prevent remote code execution. As a workaround, endorsers should not create DIDs for untrusted users. A vulnerable ledger should configure `auth_rules` to prevent new DIDs from being written to the ledger until the network can be upgraded.

CVSS3: 8.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-r6v9-p59m-gj2p

Indy's NODE_UPGRADE transaction vulnerable to remote code execution

CVSS3: 6.5
3%
Низкий
больше 3 лет назад

Уязвимостей на страницу