BIT-hyperledger-fabric-peer-2022-31121

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/hyperledger-fabric-peer/BIT-hyperledger-fabric-peer-2022-31121.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-hyperledger-fabric-peer-2022-31121
Aliases
Published
2024-07-18T19:22:12.665Z
Modified
2024-07-18T20:11:59.389749Z
Summary
[none]
Details

Hyperledger Fabric is a permissioned distributed ledger framework. In affected versions if a consensus client sends a malformed consensus request to an orderer it may crash the orderer node. A fix has been added in commit 0f1835949 which checks for missing consensus messages and returns an error to the consensus client should the message be missing. Users are advised to upgrade to versions 2.2.7 or v2.4.5. There are no known workarounds for this issue.

Database specific
{
    "cpes": [
        "cpe:2.3:a:hyperledger:fabric:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / hyperledger-fabric-peer

Package

Name
hyperledger-fabric-peer
Purl
pkg:bitnami/hyperledger-fabric-peer

Severity

  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.7
Introduced
2.3.0
Fixed
2.4.5