PT-2022-37332 · Unknown · Hyperledger Fabric

Published

2022-11-12

·

Updated

2022-11-12

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Hyperledger Fabric version 2.3
Description The issue allows attackers to cause a denial of service by repeatedly sending a crafted channel transaction with the same Channel name, leading to an orderer crash. However, the official Fabric with Raft prevents exploitation through a locking mechanism and a check for names that already exist.
Recommendations For Hyperledger Fabric version 2.3, consider implementing a locking mechanism and a check for existing channel names to prevent the denial of service attack. As a temporary workaround, restrict access to the channel creation functionality to minimize the risk of exploitation.

Fix

Related Identifiers

PYSEC-2022-43055

Affected Products

Hyperledger Fabric