CVE-2024-45244
MEDIUMHyperledger Fabric <3.0.0, <2.5.10 - Info Disclosure
Title source: llmDescription
Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.
Exploits (2)
Scores
CVSS v3
5.3
EPSS
0.0060
EPSS Percentile
69.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Classification
CWE
CWE-294
Status
published
Affected Products (2)
hyperledger/fabric
< 2.5.9
hyperledger/fabric
Go
Timeline
Published
Aug 25, 2024
Tracked Since
Feb 18, 2026