Описание
c-lightning before 0.7.1 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md states "It can be used for testing, but it should not be used for real funds."
Ссылки
- PatchThird Party Advisory
- ExploitMailing ListThird Party Advisory
- PatchThird Party Advisory
- ExploitMailing ListThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.7.1 (исключая)
cpe:2.3:a:elementsproject:c-lightning:*:*:*:*:*:*:*:*
EPSS
Процентиль: 62%
0.00432
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
больше 3 лет назад
c-lightning before 0.7.1 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md states "It can be used for testing, but it should not be used for real funds."
EPSS
Процентиль: 62%
0.00432
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
NVD-CWE-Other