PT-2022-23122 · Unknown · Hyperledger Fabric

Haosheng Wang

·

Published

2022-08-18

·

Updated

2024-07-18

·

CVE-2022-36023

CVSS v3.1

7.0

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Hyperledger Fabric versions prior to 2.4.6
Description Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. If a gateway client application sends a malformed request to a gateway peer, it may crash the peer node. The issue is resolved by checking for the malformed gateway request and returning an error to the gateway client.
Recommendations For versions prior to 2.4.6, upgrade to version 2.4.6 to resolve the issue. As a temporary workaround, consider restricting access to the gateway peer to minimize the risk of exploitation.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BIT-HYPERLEDGER-FABRIC-ORDERER-2022-36023
BIT-HYPERLEDGER-FABRIC-PEER-2022-36023
BIT-HYPERLEDGER-FABRIC-TOOLS-2022-36023
CVE-2022-36023
GHSA-QJ6R-FHRC-JJ5R

Affected Products

Hyperledger Fabric