QID 981190
QID 981190: Nodejs (npm) Security Update for insight-api (GHSA-8p2p-p8mg-x3cw)
Bitpay/insight-api Insight-api version 5.0.0 and earlier contains a CWE-20: input validation vulnerability in transaction broadcast endpoint that can result in Full Path Disclosure. This attack appear to be exploitable via Web request.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-8p2p-p8mg-x3cw for updates pertaining to this vulnerability.
Vendor References
- GHSA-8p2p-p8mg-x3cw -
github.com/advisories/GHSA-8p2p-p8mg-x3cw
CVEs related to QID 981190
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8p2p-p8mg-x3cw | insight-api |
|