Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-28937: A malicious node becomes a leader and set the view to a very large one, blocks cannot be processed · Issue #2312 · FISCO-BCOS/FISCO-BCOS

FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node, via an invalid proposal with an invalid header, will cause normal nodes to stop producing new blocks and processing new clients’ requests.

CVE
#ubuntu

Describe the bug
I setup a group with 10 nodes. One of them are malicious one. First, the malicious node starts, and after that all the other nodes start. Then I start the press testing program to send transactions to the group. And it stuck here:

To Reproduce
Steps to reproduce the behavior:

  1. setup 10 nodes
  2. start press testing program
  3. the bug occurs

Expected behavior
The system should not stuck and keep changing the view.

Screenshots

Environment (please complete the following information):

  • OS: Ubuntu 20.04
  • FISCO BCOS Version 3.0.0-rc2

Additional context
There maybe an integer overflow during the viewchange and the malicious node can always be the leader.

Related news

CVE-2022-28930: SQL injection vulnerability exists in ERP-Pro system · Issue #I515R4 · Skyeye云系列/erp-pro - Gitee.com

ERP-Pro v3.7.5 was discovered to contain a SQL injection vulnerability via the component /base/SysEveMenuAuthPointMapper.xml..

CVE-2022-28936: A malicious node may fake a proposal's header when he is the leader and some transactions cannot be processed · Issue #2307 · FISCO-BCOS/FISCO-BCOS

FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node can trigger an integer overflow and cause a Denial of Service (DoS) via an unusually large viewchange message packet.

CVE-2022-28937: A malicious node becomes a leader and set the view to a very large one, blocks cannot be processed · Issue #2312 · FISCO-BCOS/FISCO-BCOS

FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node, via an invalid proposal with an invalid header, will cause normal nodes to stop producing new blocks and processing new clients' requests.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907