CVE-2023-46132 is a medium-severity vulnerability affecting Hyperledger Fabric, an open-source permissioned distributed ledger framework. The flaw, categorized as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization), allows an attacker to manipulate transaction processing within a block by "cross-linking" transactions. This can lead to a divergence in the world state between peers, as the insecure hashing mechanism (simple concatenation) fails to detect these alterations. The vulnerability has a CVSS score of 6.5 (Medium), indicating a network-based attack with low attack complexity and requiring low privileges, resulting in high integrity impact but no confidentiality or availability impact. There are no known workarounds, and users are advised to upgrade to v2.2.14 or v2.5.5. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting a low level of public awareness or attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, < 2.2.14CPE matchmatch criteria | cpe:2.3:a:hyperledger:fabric:*:*:*:*:*:*:*:* | ||
>= 2.3.0, < 2.5.5CPE matchmatch criteria | cpe:2.3:a:hyperledger:fabric:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.