An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and decoder.readObject in crypto/ECKey.java. When a node syncs and mines a new block, arbitrary OS commands can be run on the server.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-0592 An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and decoder.readObject in crypto/ECKey.java. When a node syncs and mines a new block, arbitrary OS commands can be run on the server.
Github GHSA Github GHSA GHSA-hf4p-jm7r-vjjj Deserialization of Untrusted Data in EthereumJ
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T10:10:04.893Z

Reserved: 2018-08-26T00:00:00

Link: CVE-2018-15890

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-06-20T17:15:09.800

Modified: 2024-11-21T03:51:39.373

Link: CVE-2018-15890

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses