NULL Pointer Dereference in HyperLedger Fabric
High severity
GitHub Reviewed
Published
May 25, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Package
Affected versions
>= 2.3.0, < 2.3.3
< 2.2.4
Patched versions
2.3.3
2.2.4
Description
Published by the National Vulnerability Database
Nov 18, 2021
Published to the GitHub Advisory Database
May 25, 2022
Reviewed
May 25, 2022
Last updated
Jan 27, 2023
A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.1.0. This bug can be leveraged by constructing a message whose payload is nil and sending this message with the method 'forwardToLeader'. This bug has been admitted and fixed by the developers of Fabric. If leveraged, any leader node will crash.
References