7

CVE-2022-36023

Remote denial of service in Hyperledger Fabric Gateway

Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. If a gateway client application sends a malformed request to a gateway peer it may crash the peer node. Version 2.4.6 checks for the malformed gateway request and returns an error to the gateway client. There are no known workarounds, users must upgrade to version 2.4.6.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HyperledgerFabric Version < 2.4.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.91% 0.553
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
security-advisories@github.com 7 2.2 4.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://github.com/hyperledger/fabric/pull/3572
Patch
https://github.com/hyperledger/fabric/pull/3576
Patch
https://github.com/hyperledger/fabric/pull/3577
Patch
https://github.com/hyperledger/fabric/releases/tag/v2.4.6
Release Notes
https://github.com/hyperledger/fabric/security/advisories/GHSA-qj6r-fhrc-jj5r
Third Party Advisory