QID 983792
QID 983792: Java (maven) Security Update for org.ethereum:ethereumj-core (GHSA-hf4p-jm7r-vjjj)
An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and decoder.readObject in crypto/ECKey.java. When a node syncs and mines a new block, arbitrary OS commands can be run on the server.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-hf4p-jm7r-vjjj for updates pertaining to this vulnerability.
Vendor References
- GHSA-hf4p-jm7r-vjjj -
github.com/advisories/GHSA-hf4p-jm7r-vjjj
CVEs related to QID 983792
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hf4p-jm7r-vjjj | org.ethereum:ethereumj-core |
|