Описание
go-ethereum (Geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, through a flaw in the ECIES cryptography implementation, an attacker may be able to extract bits of the p2p node key. The issue is resolved in the v1.16.9 and v1.17.0 releases of Geth. Geth maintainers recommend rotating the node key after applying the upgrade, which can be done by removing the file <datadir>/geth/nodekey before starting Geth.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.16.9 (исключая)
cpe:2.3:a:ethereum:go_ethereum:*:*:*:*:*:*:*:*
EPSS
Процентиль: 8%
0.00027
Низкий
7.5 High
CVSS3
Дефекты
CWE-203
Связанные уязвимости
CVSS3: 7.5
debian
около 1 месяца назад
go-ethereum (Geth) is a golang execution layer implementation of the E ...
github
около 1 месяца назад
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake
EPSS
Процентиль: 8%
0.00027
Низкий
7.5 High
CVSS3
Дефекты
CWE-203