Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rqmg-hrg4-fm69

Опубликовано: 06 авг. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks

Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022.

Пакеты

Наименование

github.com/ethereum/go-ethereum

go
Затронутые версииВерсия исправления

<= 1.10.21

Отсутствует

EPSS

Процентиль: 67%
0.00541
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
больше 3 лет назад

Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022.

CVSS3: 5.9
debian
больше 3 лет назад

Go Ethereum (aka geth) through 1.10.21 allows attackers to increase re ...

EPSS

Процентиль: 67%
0.00541
Низкий

5.9 Medium

CVSS3