CVE-2021-43667

A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.1.0. This bug can be leveraged by constructing a message whose payload is nil and sending this message with the method 'forwardToLeader'. This bug has been admitted and fixed by the developers of Fabric. If leveraged, any leader node will crash.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:linuxfoundation:fabric:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:fabric:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:fabric:2.1.0:*:*:*:*:*:*:*

History

21 Nov 2024, 06:29

Type Values Removed Values Added
References () https://github.com/hyperledger/fabric/pull/2844 - Patch, Third Party Advisory () https://github.com/hyperledger/fabric/pull/2844 - Patch, Third Party Advisory
References () https://jira.hyperledger.org/browse/FAB-18529 - Exploit, Vendor Advisory () https://jira.hyperledger.org/browse/FAB-18529 - Exploit, Vendor Advisory

Information

Published : 2021-11-18 16:15

Updated : 2024-11-21 06:29


NVD link : CVE-2021-43667

Mitre link : CVE-2021-43667

CVE.ORG link : CVE-2021-43667


JSON object : View

Products Affected

linuxfoundation

  • fabric
CWE
CWE-476

NULL Pointer Dereference