PT-2018-9213 · Electrum · Electrum Bitcoin Wallet
Theymos
·
Published
2018-02-09
·
Updated
2019-10-03
·
CVE-2018-1000022
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Electrum Bitcoin Wallet versions prior to 3.0.5
Description:
The issue concerns a Missing Authorization vulnerability in the JSONRPC interface, which can lead to Bitcoin theft if the user's wallet is not password protected. This can be exploited when the victim visits a web page with specially crafted JavaScript.
Recommendations:
For versions prior to 3.0.5, update to version 3.0.5 or later to resolve the issue. As a temporary workaround, consider ensuring that the wallet is password protected to minimize the risk of exploitation.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Electrum Bitcoin Wallet