GHSA-r6v9-p59m-gj2p
Dashboard / Vulnerabilities / GHSA-r6v9-p59m-gj2p
Summary: Indy's NODE_UPGRADE transaction vulnerable to remote code execution
Details: ### Impact The `pool-upgrade` request handler in Indy-Node `<=1.12.4` allows an improperly authenticated attacker to remotely execute code on nodes within the network. Network operators are strongly encouraged to upgrade to the latest Indy-Node release `>=1.12.5` as soon as possible. ### Patches The `pool-upgrade` request handler in Indy-Node `>=1.12.5` has been updated to properly authenticate `pool-upgrade` transactions before any processing is performed by the request handler. The transactions are further sanitized to prevent remote code execution. ### Mitigations Network operators are strongly encouraged to upgrade to the latest Indy-Node release `>=1.12.5` as soon as possible. ### Acknowledgements Thank you to @shakreiner at CyberArk Labs for finding and responsibly disclosing this issue.
References: https://github.com/hyperledger/indy-node/security/advisories/GHSA-r6v9-p59m-gj2p, https://nvd.nist.gov/vuln/detail/CVE-2022-31020, https://github.com/hyperledger/indy-node/commit/fe507474f77084faef4539101e2bbb4d508a97f5, https://github.com/hyperledger/indy-node, https://github.com/hyperledger/indy-node/releases/tag/v1.12.5, https://github.com/pypa/advisory-database/tree/main/vulns/indy-node/PYSEC-2022-265.yaml
Affected packages
Package
Name: indy-node
Purl: pkg:pypi/indy-node
Affected ranges
Type: ECOSYSTEM
Events:
