CVE-2020-11090: Uncontrolled Resource Consumption in Indy Node
(updated )
Indy Node has a bug in TAA handling code. The current primary can be crashed with a malformed transaction from a client, which leads to a view change. Repeated rapid view changes have the potential of bringing down the network.
References
- github.com/advisories/GHSA-3gw4-m5w7-v89c
- github.com/hyperledger/indy-node
- github.com/hyperledger/indy-node/blob/master/CHANGELOG.md
- github.com/hyperledger/indy-node/security/advisories/GHSA-3gw4-m5w7-v89c
- github.com/pypa/advisory-database/tree/main/vulns/indy-node/PYSEC-2020-47.yaml
- nvd.nist.gov/vuln/detail/CVE-2020-11090
- pypi.org/project/indy-node/1.12.3
Detect and mitigate CVE-2020-11090 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →