Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fabric MEDIUM 5.3
CVE-2024-45244

Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.

Fix: after 2.5.9
Fix from $1,600 2024-08-25
Ursa MEDIUM 6.5
CVE-2024-22192

Ursa is a cryptographic library for use with blockchains. The revocation scheme that is part of the Ursa CL-Signatures implementations has a flaw tha…

Mitigation only
Fix from $1,600 2024-01-16
Ursa HIGH 8.1
CVE-2024-21670

Ursa is a cryptographic library for use with blockchains. The revocation schema that is part of the Ursa CL-Signatures implementations has a flaw tha…

Mitigation only
Fix from $1,950 2024-01-16
Ursa MEDIUM 5.3
CVE-2022-31021

Ursa is a cryptographic library for use with blockchains. A weakness in the Hyperledger AnonCreds specification that is not mitigated in the Ursa and…

Fix: 0.3+
Fix from $1,600 2024-01-16
Aries Cloud Agent HIGH 8.8
CVE-2024-21669

Hyperledger Aries Cloud Agent Python (ACA-Py) is a foundation for building decentralized identity applications and services running in non-mobile env…

Fix: 0.10.5+
Fix from $1,950 2024-01-11
Fabric MEDIUM 6.5
CVE-2023-46132

Hyperledger Fabric is an open source permissioned distributed ledger framework. Combining two molecules to one another, called "cross-linking" result…

Fix: 2.2.14 / 2.5.5+
Fix from $1,600 2023-11-14
Fabric HIGH 7.5
CVE-2022-45196

Hyperledger Fabric 2.3 allows attackers to cause a denial of service (orderer crash) by repeatedly sending a crafted channel tx with the same Channel…

Patch available
Fix from $1,950 2022-11-12
Fabric MEDIUM 5.3
CVE-2022-36023

Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. If a gateway client ap…

Fix: 2.4.6+
Fix from $1,600 2022-08-18
Fabric HIGH 7.5
CVE-2022-31121

Hyperledger Fabric is a permissioned distributed ledger framework. In affected versions if a consensus client sends a malformed consensus request to …

Fix: 2.2.7 / 2.4.5+
Fix from $1,950 2022-07-07
Iroha HIGH 7.5
CVE-2018-3756

Hyperledger Iroha versions v1.0_beta and v1.0.0_beta-1 are vulnerable to transaction and block signature verification bypass in the transaction and b…

Mitigation only
Fix from $1,950 2018-06-01