Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-28936: A malicious node may fake a proposal's header when he is the leader and some transactions cannot be processed · Issue #2307 · FISCO-BCOS/FISCO-BCOS

FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node can trigger an integer overflow and cause a Denial of Service (DoS) via an unusually large viewchange message packet.

CVE
#dos#java

Describe the bug
I setup a group of 10 nodes under 3.0.0-rc2 version. One of the nodes is a malicious one and tries to modify some fields when it sends out some packages. Then I use the following command to test the system:

java -cp 'conf/:lib/*:apps/*' org.fisco.bcos.sdk.demo.perf.PerformanceOk 500000 5000 group

Then some transactions cannot be processed successfully.
To Reproduce
Steps to reproduce the behavior:

Expected behavior
All the transactions should be processed correctly.

Related news

CVE-2022-28930: SQL injection vulnerability exists in ERP-Pro system · Issue #I515R4 · Skyeye云系列/erp-pro - Gitee.com

ERP-Pro v3.7.5 was discovered to contain a SQL injection vulnerability via the component /base/SysEveMenuAuthPointMapper.xml..

CVE-2022-28937: A malicious node becomes a leader and set the view to a very large one, blocks cannot be processed · Issue #2312 · FISCO-BCOS/FISCO-BCOS

FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node, via an invalid proposal with an invalid header, will cause normal nodes to stop producing new blocks and processing new clients' requests.

CVE-2022-28936: A malicious node may fake a proposal's header when he is the leader and some transactions cannot be processed · Issue #2307 · FISCO-BCOS/FISCO-BCOS

FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node can trigger an integer overflow and cause a Denial of Service (DoS) via an unusually large viewchange message packet.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907