PT-2018-9213 · Electrum · Electrum Bitcoin Wallet

Theymos

·

Published

2018-02-09

·

Updated

2019-10-03

·

CVE-2018-1000022

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Electrum Bitcoin Wallet versions prior to 3.0.5
Description: The issue concerns a Missing Authorization vulnerability in the JSONRPC interface, which can lead to Bitcoin theft if the user's wallet is not password protected. This can be exploited when the victim visits a web page with specially crafted JavaScript.
Recommendations: For versions prior to 3.0.5, update to version 3.0.5 or later to resolve the issue. As a temporary workaround, consider ensuring that the wallet is password protected to minimize the risk of exploitation.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1000022

Affected Products

Electrum Bitcoin Wallet