Description
Bitpay/insight-api Insight-api version 5.0.0 and earlier contains a CWE-20: input validation vulnerability in transaction broadcast endpoint that can result in Full Path Disclosure. This attack appear to be exploitable via Web request.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0177 | Bitpay/insight-api Insight-api version 5.0.0 and earlier contains a CWE-20: input validation vulnerability in transaction broadcast endpoint that can result in Full Path Disclosure. This attack appear to be exploitable via Web request. |
Github GHSA |
GHSA-8p2p-p8mg-x3cw | Insight API transaction broadcast endpoint can result in Full Path Disclosure |
References
| Link | Providers |
|---|---|
| https://github.com/bitpay/insight-api/issues/542 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T12:33:48.735Z
Reserved: 2018-01-29T00:00:00.000Z
Link: CVE-2018-1000023
No data.
Status : Modified
Published: 2018-02-09T23:29:00.667
Modified: 2024-11-21T03:39:26.987
Link: CVE-2018-1000023
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA