CVE-2020-11090

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
11/06/2020
Last modified:
22/06/2020

Description

In Indy Node 1.12.2, there is an Uncontrolled Resource Consumption vulnerability. Indy Node has a bug in TAA handling code. The current primary can be crashed with a malformed transaction from a client, which leads to a view change. Repeated rapid view changes have the potential of bringing down the network. This is fixed in version 1.12.3.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:linuxfoundation:indy-node:1.12.2:*:*:*:*:*:*:*