HIGH7.5
GHSA-vjj6-5m9f-wqjw
NULL Pointer Dereference in HyperLedger Fabric
Quick fix
GHSA-vjj6-5m9f-wqjw — github.com/hyperledger/fabric: upgrade to the fixed version with the command below.
go get github.com/hyperledger/fabric@v2.3.3Details
A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.1.0. This bug can be leveraged by constructing a message whose payload is nil and sending this message with the method 'forwardToLeader'. This bug has been admitted and fixed by the developers of Fabric. If leveraged, any leader node will crash.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hyperledger/fabric
Introduced in:
2.3.0Fixed in: 2.3.3Fix
go get github.com/hyperledger/fabric@v2.3.3Go/github.com/hyperledger/fabric
Introduced in:
0Fixed in: 2.2.4Fix
go get github.com/hyperledger/fabric@v2.2.4