VulnerabilityModified
CVE-2022-36023
If a gateway client application sends a malformed request to a gateway peer it may crash the peer node.
MEDIUM 5.3EPSS 1.10%
Does this matter?
Lower severity and a low EPSS score (1.10%). Track it; it rarely justifies an emergency change on its own.
Description
Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. If a gateway client application sends a malformed request to a gateway peer it may crash the peer node. Version 2.4.6 checks for the malformed gateway request and returns an error to the gateway client. There are no known workarounds, users must upgrade to version 2.4.6.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 1.10% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- hyperledger/fabric
- Source
- security-advisories@github.com
References
- https://github.com/hyperledger/fabric/pull/3572Patch
- https://github.com/hyperledger/fabric/pull/3576Patch
- https://github.com/hyperledger/fabric/pull/3577Patch
- https://github.com/hyperledger/fabric/releases/tag/v2.4.6Release Notes
- https://github.com/hyperledger/fabric/security/advisories/GHSA-qj6r-fhrc-jj5rThird Party Advisory
- https://github.com/hyperledger/fabric/pull/3572Patch
- https://github.com/hyperledger/fabric/pull/3576Patch
- https://github.com/hyperledger/fabric/pull/3577Patch
- https://github.com/hyperledger/fabric/releases/tag/v2.4.6Release Notes
- https://github.com/hyperledger/fabric/security/advisories/GHSA-qj6r-fhrc-jj5rThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.