SB2022070758 - Input validation error in Fabric
Published: July 7, 2022 Updated: April 23, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Input validation error (CVE-ID: CVE-2022-31121)
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper input validation in consensus request handling in orderer/common/cluster when processing malformed consensus requests. A remote user can send a malformed consensus request to cause a denial of service.
Remediation
Install update from vendor's website.