Описание
bitcoind in Bitcoin Core through 0.21.0 can create a new file in an arbitrary directory (e.g., outside the ~/.bitcoin directory) via a dumpwallet RPC call. NOTE: this reportedly does not violate the security model of Bitcoin Core, but can violate the security model of a fork that has implemented dumpwallet restrictions
Ссылки
- ExploitIssue TrackingThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.21.0 (включая)
cpe:2.3:a:bitcoin:bitcoin_core:*:*:*:*:*:*:*:*
EPSS
Процентиль: 54%
0.00315
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-20
Связанные уязвимости
CVSS3: 7.5
debian
около 5 лет назад
bitcoind in Bitcoin Core through 0.21.0 can create a new file in an ar ...
CVSS3: 7.5
github
больше 3 лет назад
bitcoind in Bitcoin Core through 0.21.0 can create a new file in an arbitrary directory (e.g., outside the ~/.bitcoin directory) via a dumpwallet RPC call.
EPSS
Процентиль: 54%
0.00315
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-20