PT-2022-27426 · Hyperledger · Hyperledger Fabric

Govulnbot

·

Published

2022-11-12

·

Updated

2024-07-18

·

CVE-2022-45196

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Hyperledger Fabric version 2.3
Description The issue allows attackers to cause a denial of service by repeatedly sending a crafted channel transaction with the same channel name, leading to an orderer crash. However, the official Fabric with Raft prevents exploitation through a locking mechanism and a check for existing names.
Recommendations For Hyperledger Fabric version 2.3, consider implementing a locking mechanism and a check for existing channel names to prevent the denial of service attack, similar to the official Fabric with Raft.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BIT-HYPERLEDGER-FABRIC-ORDERER-2022-45196
BIT-HYPERLEDGER-FABRIC-PEER-2022-45196
BIT-HYPERLEDGER-FABRIC-TOOLS-2022-45196
CVE-2022-45196

Affected Products

Hyperledger Fabric