Vendor
high
advisory
SSRF Vulnerability in Hyperledger FireFly Webhook Subscription Component
1 TTP 1 CVEHyperledger FireFly versions 1.4.0 and earlier contain an SSRF vulnerability in the Webhook Subscription component, allowing unauthenticated remote attackers to perform unauthorized requests via manipulation of the URL argument.
FireFly
1t
1c
critical
advisory
Hyperledger Fabric SDK Java Deserialization RCE
2 rules 1 TTPThe deprecated fabric-sdk-java client SDK is vulnerable to Java deserialization RCE due to the use of ObjectInputStream.readObject() without an ObjectInputFilter in Channel.java, allowing remote code execution if an attacker can supply crafted serialized Channel bytes to the client application.
fabric-sdk-java
deserialization
rce
java
2r
1t