CVE-2023-46132
HighAdvisory
Published 14 Nov 2023In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.1
- base score, highest
- EPSS
- 0.005
- 43rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 6
- of 17,781 indexed, latest versions
- Container images
- 7
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Fabric vulnerable to crosslinking transaction attack
Carried by container images the latest versions of 6 of 17,781 indexed charts deploy, on 7 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| github.com/ | v1.4.11, v2.4.9 | 2.2.14, 2.5.5 | 7 |
- OSV records
- GHSA-v9w2-543f-h69m
- Also known as
- BIT-hyperledger-fabric-orderer-2023-46132, BIT-hyperledger-fabric-peer-2023-46132, BIT-hyperledger-fabric-tools-2023-46132
Charts affected
6 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| dltbrokerassist-iot-distributed-broker | 0.2.0 | 3 of 9See more | 77,706 |
| dltloggingassist-iot-logging-auditing | 0.2.0 | 3 of 9See more | 77,687 |
| hlf-caowkin | 2.1.0 | 1 of 2See more | 3,424 |
| hlf-k8ssubstraVerified publisher | 10.2.4 | 3 of 7See more | 12,006 |
| dltkvassist-iot-data-integrity-verification | 0.2.0 | 3 of 9See more | 77,706 |
| dltflassist-iot-dlt-based-fl | 0.2.0 | 3 of 9See more | 77,706 |
Container images carrying it
7 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| hyperledger/ | 6ec3fe59ea55 | github.com/ | 2.5.5 | 4 |
| hyperledger/ | 6ff36af21eb1 | github.com/ | 2.5.5 | 4 |
| hyperledger/ | b1194f509085 | github.com/ | 2.5.5 | 4 |
| hyperledger/ | c7f3422ec1d5 | github.com/ | 2.2.14 | 1 |
| hyperledger/ | f270dfeee91d | github.com/ | 2.2.14 | 1 |
| ghcr.io/ | f681e0343a31 | github.com/ | 2.5.5 | 1 |
| ghcr.io/ | 3491a0f31c4a | github.com/ | 2.5.5 | 1 |