A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.0.1, v2.3.0. It can easily break down as many orderers as the attacker wants. This bug can be leveraged by constructing a message whose header is invalid to the interface Order. This bug has been admitted and fixed by the developers of Fabric.
{
"cpe": [
"cpe:2.3:a:linuxfoundation:fabric:1.4.0:*:*:*:*:*:*:*",
"cpe:2.3:a:linuxfoundation:fabric:2.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:linuxfoundation:fabric:2.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:linuxfoundation:fabric:2.3.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"extracted_events": [
{
"introduced": "1.4.0"
},
{
"last_affected": "1.4.0"
},
{
"introduced": "2.0.0"
},
{
"last_affected": "2.0.0"
},
{
"introduced": "2.0.1"
},
{
"last_affected": "2.0.1"
},
{
"introduced": "2.3.0"
},
{
"last_affected": "2.3.0"
}
]
}