CVE-2022-36023

Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. If a gateway client application sends a malformed request to a gateway peer it may crash the peer node. Version 2.4.6 checks for the malformed gateway request and returns an error to the gateway client. There are no known workarounds, users must upgrade to version 2.4.6.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hyperledger:fabric:*:*:*:*:*:*:*:*

History

16 Feb 2023, 02:32

Type Values Removed Values Added
References (CONFIRM) https://github.com/hyperledger/fabric/security/advisories/GHSA-qj6r-fhrc-jj5r - Release Notes, Third Party Advisory (CONFIRM) https://github.com/hyperledger/fabric/security/advisories/GHSA-qj6r-fhrc-jj5r - Third Party Advisory
References (MISC) https://github.com/hyperledger/fabric/pull/3576 - (MISC) https://github.com/hyperledger/fabric/pull/3576 - Patch
References (MISC) https://github.com/hyperledger/fabric/pull/3577 - (MISC) https://github.com/hyperledger/fabric/pull/3577 - Patch
References (MISC) https://github.com/hyperledger/fabric/pull/3572 - (MISC) https://github.com/hyperledger/fabric/pull/3572 - Patch

13 Dec 2022, 23:15

Type Values Removed Values Added
References
  • (MISC) https://github.com/hyperledger/fabric/pull/3576 -
  • (MISC) https://github.com/hyperledger/fabric/pull/3577 -
  • (MISC) https://github.com/hyperledger/fabric/pull/3572 -

19 Aug 2022, 15:53

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:a:hyperledger:fabric:*:*:*:*:*:*:*:*
References (MISC) https://github.com/hyperledger/fabric/releases/tag/v2.4.6 - (MISC) https://github.com/hyperledger/fabric/releases/tag/v2.4.6 - Release Notes, Third Party Advisory
References (CONFIRM) https://github.com/hyperledger/fabric/security/advisories/GHSA-qj6r-fhrc-jj5r - (CONFIRM) https://github.com/hyperledger/fabric/security/advisories/GHSA-qj6r-fhrc-jj5r - Release Notes, Third Party Advisory
First Time Hyperledger
Hyperledger fabric

18 Aug 2022, 17:11

Type Values Removed Values Added
New CVE

Information

Published : 2022-08-18 16:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-36023

Mitre link : CVE-2022-36023

CVE.ORG link : CVE-2022-36023


JSON object : View

Products Affected

hyperledger

  • fabric
CWE
CWE-20

Improper Input Validation