Описание
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022.
Ссылки
- Broken Link
- ExploitThird Party Advisory
- Third Party Advisory
- Broken Link
- ExploitThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.10.21 (включая)
cpe:2.3:a:ethereum:go_ethereum:*:*:*:*:*:*:*:*
EPSS
Процентиль: 67%
0.00541
Низкий
5.9 Medium
CVSS3
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 5.9
debian
больше 3 лет назад
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase re ...
CVSS3: 5.9
github
больше 3 лет назад
Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks
EPSS
Процентиль: 67%
0.00541
Низкий
5.9 Medium
CVSS3
Дефекты
NVD-CWE-noinfo