hyperledger kayıtları
hyperledger üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %45,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-347 Improper Verification of Cryptographic Signature2
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm2
- CWE-20 Improper Input Validation2
- CWE-502 Deserialization of Untrusted Data1
- CWE-670 Always-Incorrect Control Flow Implementation1
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
37İzleyin | CVE-2026-41586İstismar yok | ObjectInputStream.readObject() without ObjectInputFilter in fabric-sdk-java allows Java deserialization RCEhyperledger · fabric · CWE-502 | Kritik9,3 | — | %0,6 | 7 May 2026 |
35İzleyin | CVE-2024-21669İstismar yok | Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VChyperledger · aries cloud agent · CWE-347 | Yüksek8,8 | — | %0,6 | 11 Oca 2024 |
32İzleyin | CVE-2024-21670İstismar yok | CL-Signatures Revocation Scheme in Ursa has flaws that allow a holder to demonstrate non-revocation of a revoked credentialhyperledger · ursa · CWE-327 | Yüksek8,1 | — | %0,3 | 16 Oca 2024 |
31İzleyin | CVE-2022-31121İstismar yok | Improper Input Validation in fabric hyperledgerhyperledger · fabric · CWE-20 | Yüksek7,5 | — | %2,1 | 7 Tem 2022 |
30İzleyin | CVE-2022-45196İstismar yok | Hyperledger Fabric 2.3 allows attackers to cause a denial of service (orderer crash) by repeatedly sending a crafted channel tx with the samhyperledger · fabric · CWE-670 | Yüksek7,5 | — | %0,9 | 12 Kas 2022 |
30İzleyin | CVE-2018-3756İstismar yok | Hyperledger Iroha versions v1.0_beta and v1.0.0_beta-1 are vulnerable to transaction and block signature verification bypass in the transacthyperledger · iroha · CWE-347 | Yüksek7,5 | — | %0,8 | 1 Haz 2018 |
26İzleyin | CVE-2023-46132İstismar yok | Crosslinking transaction attack in hyperledger/fabrichyperledger · fabric · CWE-362 | Orta6,5 | — | %0,5 | 14 Kas 2023 |
26İzleyin | CVE-2024-22192İstismar yok | Ursa CL-Signatures Revocation allows verifiers to generate unique identifiers for holdershyperledger · ursa · CWE-327 | Orta6,5 | — | %0,3 | 16 Oca 2024 |
21İzleyin | CVE-2022-36023İstismar yok | Remote denial of service in Hyperledger Fabric Gatewayhyperledger · fabric · CWE-20 | Orta5,3 | — | %1,1 | 18 Ağu 2022 |
21İzleyin | CVE-2024-45244Kavram kanıtı | Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.hyperledger · fabric · CWE-294 | Orta5,3 | — | %0,6 | 24 Ağu 2024 |
21İzleyin | CVE-2022-31021İstismar yok | Unlinkability broken in ursa when verifiers use malicious keyshyperledger · ursa · CWE-829 | Orta5,3 | — | %0,4 | 16 Oca 2024 |
- CVE-2026-4158637İzleyin
ObjectInputStream.readObject() without ObjectInputFilter in fabric-sdk-java allows Java deserialization RCE
KritikCVSS 9,3İstismar yokEPSS %1hyperledger · fabric7 May 2026
- CVE-2024-2166935İzleyin
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
YüksekCVSS 8,8İstismar yokEPSS %1hyperledger · aries cloud agent11 Oca 2024
- CVE-2024-2167032İzleyin
CL-Signatures Revocation Scheme in Ursa has flaws that allow a holder to demonstrate non-revocation of a revoked credential
YüksekCVSS 8,1İstismar yokEPSS %0hyperledger · ursa16 Oca 2024
- CVE-2022-3112131İzleyin
Improper Input Validation in fabric hyperledger
YüksekCVSS 7,5İstismar yokEPSS %2hyperledger · fabric7 Tem 2022
- CVE-2022-4519630İzleyin
Hyperledger Fabric 2.3 allows attackers to cause a denial of service (orderer crash) by repeatedly sending a crafted channel tx with the sam
YüksekCVSS 7,5İstismar yokEPSS %1hyperledger · fabric12 Kas 2022
- CVE-2018-375630İzleyin
Hyperledger Iroha versions v1.0_beta and v1.0.0_beta-1 are vulnerable to transaction and block signature verification bypass in the transact
YüksekCVSS 7,5İstismar yokEPSS %1hyperledger · iroha1 Haz 2018
- CVE-2023-4613226İzleyin
Crosslinking transaction attack in hyperledger/fabric
OrtaCVSS 6,5İstismar yokEPSS %1hyperledger · fabric14 Kas 2023
- CVE-2024-2219226İzleyin
Ursa CL-Signatures Revocation allows verifiers to generate unique identifiers for holders
OrtaCVSS 6,5İstismar yokEPSS %0hyperledger · ursa16 Oca 2024
- CVE-2022-3602321İzleyin
Remote denial of service in Hyperledger Fabric Gateway
OrtaCVSS 5,3İstismar yokEPSS %1hyperledger · fabric18 Ağu 2022
- CVE-2024-4524421İzleyin
Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.
OrtaCVSS 5,3Kavram kanıtıEPSS %1hyperledger · fabric24 Ağu 2024
- CVE-2022-3102121İzleyin
Unlinkability broken in ursa when verifiers use malicious keys
OrtaCVSS 5,3İstismar yokEPSS %0hyperledger · ursa16 Oca 2024