HIGH
Remote denial of service in Hyperledger Fabric Gateway
Published Aug 18, 2022
7.0
HIGHCVSS 3.1
EPSS 1.10%
Description
Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. If a gateway client application sends a malformed request to a gateway peer it may crash the peer node. Version 2.4.6 checks for the malformed gateway request and returns an error to the gateway client. There are no known workarounds, users must upgrade to version 2.4.6.
Affected products
-
- Version < 2.4.6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Hyperledger | Fabric | n/a |
|
- < 2.4.6
No data.
No Red Hat product state for this CVE.
github.com/hyperledger/fabric
Go
Introduced 2.4.0 Fixed 2.4.6
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/hyperledger/fabric | 2.4.0 | 2.4.6 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-7152 Advisory
- https://github.com/advisories/GHSA-qj6r-fhrc-jj5r Advisory
- https://github.com/hyperledger/fabric/pull/3572 Patch
- https://github.com/hyperledger/fabric/pull/3576 Patch
- https://github.com/hyperledger/fabric/pull/3577 Patch
- https://github.com/hyperledger/fabric/releases/tag/v2.4.6 Release Notes
- https://github.com/hyperledger/fabric/security/advisories/GHSA-qj6r-fhrc-jj5r Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-36023
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 18, 2022
Updated Apr 23, 2025
Reserved Jul 15, 2022
Link CVE-2022-36023
CISA Vulnrichment
Updated Apr 23, 2025
ENISA EUVD
EUVD-2022-7152 GHSA-QJ6R-FHRC-JJ5R Assigner GitHub_M
Published Aug 18, 2022
Updated Apr 23, 2025
Exploited since n/a
Link EUVD-2022-7152