目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2022-31006— Indy Node 资源管理错误漏洞

一分钟漏洞结论

影响对象
hyperledger indy-node
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Indy Node是美国Hyperledger开源的一种分布式账本的服务器部分。专为去中心化身份构建。 Indy Node 存在资源管理错误漏洞,该漏洞源于攻击者可以使用indy-node存储库中提供的指导部署最大化分类帐允许的客户端连接数,从而使分类帐无法用于其预期目的。

CVSS 7.5 · High EPSS 1.13% · P65

可能的 ATT&CK 技术 1 AI

T1499 · Endpoint Denial of Service
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2022-31006 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Hyperledger Indy DOS vulnerability
来源: CVE Program / CVE List V5
Vulnerability Description
indy-node is the server portion of Hyperledger Indy, a distributed ledger purpose-built for decentralized identity. In vulnerable versions of indy-node, an attacker can max out the number of client connections allowed by the ledger, leaving the ledger unable to be used for its intended purpose. However, the ledger content will not be impacted and the ledger will resume functioning after the attack. This attack exploits the trade-off between resilience and availability. Any protection against abusive client connections will also prevent the network being accessed by certain legitimate users. As a result, validator nodes must tune their firewall rules to ensure the right trade-off for their network's expected users. The guidance to network operators for the use of firewall rules in the deployment of Indy networks has been modified to better protect against denial of service attacks by increasing the cost and complexity in mounting such attacks. The mitigation for this vulnerability is not in the Hyperledger Indy code per se, but rather in the individual deployments of Indy. The mitigations should be applied to all deployments of Indy, and are not related to a particular release.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
未加控制的资源消耗(资源穷尽)
来源: CVE Program / CVE List V5
Vulnerability Title
Indy Node 资源管理错误漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Indy Node是美国Hyperledger开源的一种分布式账本的服务器部分。专为去中心化身份构建。 Indy Node 存在资源管理错误漏洞,该漏洞源于攻击者可以使用indy-node存储库中提供的指导部署最大化分类帐允许的客户端连接数,从而使分类帐无法用于其预期目的。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
hyperledger indy-node <= 1.12.6 -

二、漏洞 CVE-2022-31006 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2022-31006 的情报信息

请登录查看更多情报信息。

CVE-2022-31006 补丁与修复 (1)

CVE-2022-31006 厂商安全公告 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2022-31006

暂无评论


发表评论