CVE-2022-36023

Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. If a gateway client application sends a malformed request to a gateway peer it may crash the peer node. Version 2.4.6 checks for the malformed gateway request and returns an error to the gateway client. There are no known workarounds, users must upgrade to version 2.4.6.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hyperledger:fabric:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:12

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 7.0
References () https://github.com/hyperledger/fabric/pull/3572 - Patch () https://github.com/hyperledger/fabric/pull/3572 - Patch
References () https://github.com/hyperledger/fabric/pull/3576 - Patch () https://github.com/hyperledger/fabric/pull/3576 - Patch
References () https://github.com/hyperledger/fabric/pull/3577 - Patch () https://github.com/hyperledger/fabric/pull/3577 - Patch
References () https://github.com/hyperledger/fabric/releases/tag/v2.4.6 - Release Notes () https://github.com/hyperledger/fabric/releases/tag/v2.4.6 - Release Notes
References () https://github.com/hyperledger/fabric/security/advisories/GHSA-qj6r-fhrc-jj5r - Third Party Advisory () https://github.com/hyperledger/fabric/security/advisories/GHSA-qj6r-fhrc-jj5r - Third Party Advisory

Information

Published : 2022-08-18 16:15

Updated : 2024-11-21 07:12


NVD link : CVE-2022-36023

Mitre link : CVE-2022-36023

CVE.ORG link : CVE-2022-36023


JSON object : View

Products Affected

hyperledger

  • fabric
CWE
CWE-20

Improper Input Validation