Bitpay/insight-api Insight-api version 5.0.0 and earlier contains a CWE-20: input validation vulnerability in transaction broadcast endpoint that can result in Full Path Disclosure. This attack appear to be exploitable via Web request.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0177 | Bitpay/insight-api Insight-api version 5.0.0 and earlier contains a CWE-20: input validation vulnerability in transaction broadcast endpoint that can result in Full Path Disclosure. This attack appear to be exploitable via Web request. |
Github GHSA |
GHSA-8p2p-p8mg-x3cw | Insight API transaction broadcast endpoint can result in Full Path Disclosure |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/bitpay/insight-api/issues/542 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T12:33:48.735Z
Reserved: 2018-01-29T00:00:00.000Z
Link: CVE-2018-1000023
No data.
Status : Modified
Published: 2018-02-09T23:29:00.667
Modified: 2024-11-21T03:39:26.987
Link: CVE-2018-1000023
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA