CVE-2018-20587
Summary
| CVE | CVE-2018-20587 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-02-11 12:29:00 UTC |
| Updated | 2023-11-07 02:56:00 UTC |
| Description | Bitcoin Core 0.12.0 through 0.17.1 and Bitcoin Knots 0.12.0 through 0.17.x before 0.17.1.knots20181229 have Incorrect Access Control. Local users can exploit this to steal currency by binding the RPC IPv4 localhost port, and forwarding requests to the IPv6 localhost port. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bitcoin | Bitcoin Core | All | All | All | All |
| Application | Bitcoinknots | Bitcoin Knots | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Common Vulnerabilities and Exposures - Bitcoin | MISC | en.bitcoin.it | Third Party Advisory |
| CVE-2018–20587 Advisory and Full Disclosure (Bitcoin Core & Knots, on multiuser systems) | MISC | medium.com | Third Party Advisory |
| CVE-2018–20587 Advisory and Full Disclosure (Bitcoin Core & Knots, on multiuser systems) | medium.com | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.