CVE-2018-3756
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/06/2018
Last modified:
18/07/2018
Description
Hyperledger Iroha versions v1.0_beta and v1.0.0_beta-1 are vulnerable to transaction and block signature verification bypass in the transaction and block validator allowing a single node to sign a transaction and/or block multiple times, each with a random nonce, and have other validating nodes accept them as separate valid signatures.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:hyperledger:iroha:1.0:beta:*:*:*:*:*:* | ||
| cpe:2.3:a:hyperledger:iroha:1.0.0:beta1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



