PT-2022-22660 · Unknown · Hyperledger Fabric

Published

2022-09-23

·

Updated

2022-12-20

·

CVE-2022-35253

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Hyperledger Fabric versions prior to 2.4.6
Description A vulnerability exists in Hyperledger Fabric that could allow an attacker to construct a non-validated request, potentially causing a denial of service attack. The peer gateway service fails to check the proposal fields for validity, which could lead to a malformed proposal crashing the peer service.
Recommendations For Hyperledger Fabric versions prior to 2.4.6, update to version 2.4.6 to resolve the issue. As a temporary workaround, consider implementing additional validation checks on proposal fields to prevent malformed proposals from crashing the peer service. Restrict access to the peer gateway service to minimize the risk of exploitation until the update can be applied.

Fix

RCE

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2022-35253
GHSA-9W7J-Q3XW-P9VH

Affected Products

Hyperledger Fabric