Описание
An integer overflow has been found in the the latest version of Issuer. The total issuedCount can be zero if the parameter is overly large. An attacker can obtain the private key of the owner issued with a certain 'amount', and the issuedCount can be zero if there is an overflow.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:issuer_project:issuer:-:*:*:*:*:*:*:*
EPSS
Процентиль: 54%
0.00316
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-190
Связанные уязвимости
github
больше 3 лет назад
An integer overflow has been found in the the latest version of Issuer. The total issuedCount can be zero if the parameter is overly large. An attacker can obtain the private key of the owner issued with a certain 'amount', and the issuedCount can be zero if there is an overflow.
EPSS
Процентиль: 54%
0.00316
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-190