Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vulndb: potential Go vuln in github.com/hyperledger/fabric: GHSA-48gg-32q2-4r6m #3099

Closed
GoVulnBot opened this issue Aug 26, 2024 · 1 comment
Labels

Comments

@GoVulnBot
Copy link

Advisory GHSA-48gg-32q2-4r6m references a vulnerability in the following Go modules:

Module
github.com/hyperledger/fabric

Description:
Hyperledger Fabric through 2.5.9 does not verify that a request has a timestamp within the expected time window.

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/hyperledger/fabric
      vulnerable_at: 1.4.12
summary: |-
    Hyperledger Fabric does not verify request has a timestamp within the expected
    time window in github.com/hyperledger/fabric
cves:
    - CVE-2024-45244
ghsas:
    - GHSA-48gg-32q2-4r6m
references:
    - advisory: https://github.com/advisories/GHSA-48gg-32q2-4r6m
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-45244
    - fix: https://github.com/hyperledger/fabric/commit/155457a6624b3c74b22e5729c35c8499bfe952cd
source:
    id: GHSA-48gg-32q2-4r6m
    created: 2024-08-26T15:01:16.059080288Z
review_status: UNREVIEWED

@gopherbot
Copy link
Contributor

Change https://go.dev/cl/609141 mentions this issue: data/reports: add 21 unreviewed reports

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants
@tatianab @gopherbot @GoVulnBot and others