A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.0.1, v2.3.0. It can easily break down as many orderers as the attacker wants. This bug can be leveraged by constructing a message whose header is invalid to the interface Order. This bug has been admitted and fixed by the developers of Fabric.
{ "github_reviewed_at": "2021-11-24T19:42:20Z", "cwe_ids": [ "CWE-444" ], "severity": "HIGH", "nvd_published_at": "2021-11-18T16:15:00Z", "github_reviewed": true }