Записи hyperledger
11 опубликованных записей вендора hyperledger.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 45,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-347 Improper Verification of Cryptographic Signature2
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm2
- CWE-20 Improper Input Validation2
- CWE-502 Deserialization of Untrusted Data1
- CWE-670 Always-Incorrect Control Flow Implementation1
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
37Наблюдать | CVE-2026-41586Эксплойта нет | ObjectInputStream.readObject() without ObjectInputFilter in fabric-sdk-java allows Java deserialization RCEhyperledger · fabric · CWE-502 | Критическая9,3 | — | 0,6 % | 7 мая 2026 г. |
35Наблюдать | CVE-2024-21669Эксплойта нет | Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VChyperledger · aries cloud agent · CWE-347 | Высокая8,8 | — | 0,6 % | 11 янв. 2024 г. |
32Наблюдать | CVE-2024-21670Эксплойта нет | CL-Signatures Revocation Scheme in Ursa has flaws that allow a holder to demonstrate non-revocation of a revoked credentialhyperledger · ursa · CWE-327 | Высокая8,1 | — | 0,3 % | 16 янв. 2024 г. |
31Наблюдать | CVE-2022-31121Эксплойта нет | Improper Input Validation in fabric hyperledgerhyperledger · fabric · CWE-20 | Высокая7,5 | — | 2,1 % | 7 июл. 2022 г. |
30Наблюдать | CVE-2022-45196Эксплойта нет | Hyperledger Fabric 2.3 allows attackers to cause a denial of service (orderer crash) by repeatedly sending a crafted channel tx with the samhyperledger · fabric · CWE-670 | Высокая7,5 | — | 0,9 % | 12 нояб. 2022 г. |
30Наблюдать | CVE-2018-3756Эксплойта нет | Hyperledger Iroha versions v1.0_beta and v1.0.0_beta-1 are vulnerable to transaction and block signature verification bypass in the transacthyperledger · iroha · CWE-347 | Высокая7,5 | — | 0,8 % | 1 июн. 2018 г. |
26Наблюдать | CVE-2023-46132Эксплойта нет | Crosslinking transaction attack in hyperledger/fabrichyperledger · fabric · CWE-362 | Средняя6,5 | — | 0,5 % | 14 нояб. 2023 г. |
26Наблюдать | CVE-2024-22192Эксплойта нет | Ursa CL-Signatures Revocation allows verifiers to generate unique identifiers for holdershyperledger · ursa · CWE-327 | Средняя6,5 | — | 0,3 % | 16 янв. 2024 г. |
21Наблюдать | CVE-2022-36023Эксплойта нет | Remote denial of service in Hyperledger Fabric Gatewayhyperledger · fabric · CWE-20 | Средняя5,3 | — | 1,1 % | 18 авг. 2022 г. |
21Наблюдать | CVE-2024-45244Proof of concept | Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.hyperledger · fabric · CWE-294 | Средняя5,3 | — | 0,6 % | 24 авг. 2024 г. |
21Наблюдать | CVE-2022-31021Эксплойта нет | Unlinkability broken in ursa when verifiers use malicious keyshyperledger · ursa · CWE-829 | Средняя5,3 | — | 0,4 % | 16 янв. 2024 г. |
- CVE-2026-4158637Наблюдать
ObjectInputStream.readObject() without ObjectInputFilter in fabric-sdk-java allows Java deserialization RCE
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %hyperledger · fabric7 мая 2026 г.
- CVE-2024-2166935Наблюдать
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %hyperledger · aries cloud agent11 янв. 2024 г.
- CVE-2024-2167032Наблюдать
CL-Signatures Revocation Scheme in Ursa has flaws that allow a holder to demonstrate non-revocation of a revoked credential
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %hyperledger · ursa16 янв. 2024 г.
- CVE-2022-3112131Наблюдать
Improper Input Validation in fabric hyperledger
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %hyperledger · fabric7 июл. 2022 г.
- CVE-2022-4519630Наблюдать
Hyperledger Fabric 2.3 allows attackers to cause a denial of service (orderer crash) by repeatedly sending a crafted channel tx with the sam
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %hyperledger · fabric12 нояб. 2022 г.
- CVE-2018-375630Наблюдать
Hyperledger Iroha versions v1.0_beta and v1.0.0_beta-1 are vulnerable to transaction and block signature verification bypass in the transact
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %hyperledger · iroha1 июн. 2018 г.
- CVE-2023-4613226Наблюдать
Crosslinking transaction attack in hyperledger/fabric
СредняяCVSS 6,5Эксплойта нетEPSS 1 %hyperledger · fabric14 нояб. 2023 г.
- CVE-2024-2219226Наблюдать
Ursa CL-Signatures Revocation allows verifiers to generate unique identifiers for holders
СредняяCVSS 6,5Эксплойта нетEPSS 0 %hyperledger · ursa16 янв. 2024 г.
- CVE-2022-3602321Наблюдать
Remote denial of service in Hyperledger Fabric Gateway
СредняяCVSS 5,3Эксплойта нетEPSS 1 %hyperledger · fabric18 авг. 2022 г.
- CVE-2024-4524421Наблюдать
Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.
СредняяCVSS 5,3Proof of conceptEPSS 1 %hyperledger · fabric24 авг. 2024 г.
- CVE-2022-3102121Наблюдать
Unlinkability broken in ursa when verifiers use malicious keys
СредняяCVSS 5,3Эксплойта нетEPSS 0 %hyperledger · ursa16 янв. 2024 г.