Bitcoin Core 0.12.0 through 0.17.1 and Bitcoin Knots 0.12.0 through 0.17.x before 0.17.1.knots20181229 have Incorrect Access Control. Local users can exploit this to steal currency by binding the RPC IPv4 localhost port, and forwarding requests to the IPv6 localhost port.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-02-11T12:00:00
Updated: 2024-08-05T12:05:17.687Z
Reserved: 2018-12-30T00:00:00
Link: CVE-2018-20587
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-02-11T12:29:00.250
Modified: 2024-11-21T04:01:47.563
Link: CVE-2018-20587
Redhat
No data.