Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2022-31020

Remote code execution in Indy's NODE_UPGRADE transaction
Back to all
CVE

CVE-2022-31020

Remote code execution in Indy's NODE_UPGRADE transaction

Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In versions 1.12.4 and prior, the pool-upgrade request handler in Indy-Node allows an improperly authenticated attacker to remotely execute code on nodes within the network. The pool-upgrade request handler in Indy-Node 1.12.5 has been updated to properly authenticate pool-upgrade transactions before any processing is performed by the request handler. The transactions are further sanitized to prevent remote code execution. As a workaround, endorsers should not create DIDs for untrusted users. A vulnerable ledger should configure auth_rules to prevent new DIDs from being written to the ledger until the network can be upgraded.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
8.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://github.com/hyperledger/indy-node/releases/tag/v1.12.5, https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/31xxx/CVE-2022-31020.json, https://github.com/hyperledger/indy-node/security/advisories/GHSA-r6v9-p59m-gj2p, https://nvd.nist.gov/vuln/detail/CVE-2022-31020, https://github.com/hyperledger/indy-node/commit/fe507474f77084faef4539101e2bbb4d508a97f5

Severity

8.8

CVSS Score
0
10

Basic Information

Ecosystem
Base CVSS
8.8
EPSS Probability
0.02116%
EPSS Percentile
0.84164%
Introduced Version
0
Fix Available
51a6ebba62be9c16254bc17520ef7777e5e89942

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading