Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: python314Packages.dtfabric

Found 1 matching suggestions

View:
Compact
Detailed
Untriaged
created 2 weeks, 4 days ago Activity log
  • Created suggestion
ObjectInputStream.readObject() without ObjectInputFilter in fabric-sdk-java allows Java deserialization RCE

Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to 2.2.26, Channel.java implements readObject() and exposes deSerializeChannel() which call ObjectInputStream.readObject() on untrusted byte arrays without configuring an ObjectInputFilter. This is a classic Java deserialization RCE pattern. At time of publication, there are no publicly available patches.

Affected products

fabric
  • ==>= 1.0.0, <= 2.2.26

Matching in nixpkgs

pkgs.fabric-ai

Fabric is an open-source framework for augmenting humans using AI. It provides a modular framework for solving specific problems using a crowdsourced set of AI prompts that can be used anywhere