PT-2021-19612 · Unknown+1 · Bitcoin Core+1

Florian Mathieu

+1

·

Published

2021-01-21

·

Updated

2024-08-03

·

CVE-2021-3195

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Bitcoin Core versions through 0.21.0
Description: The issue allows bitcoind to create a new file in an arbitrary directory, such as outside the ~/.bitcoin directory, via a "dumpwallet" RPC call. This reportedly does not violate the security model of Bitcoin Core but can violate the security model of a fork that has implemented dumpwallet restrictions.
Recommendations: For versions through 0.21.0, as a temporary workaround, consider restricting the use of the "dumpwallet" RPC call until a more permanent solution is available. Restrict access to arbitrary directories to minimize the risk of exploitation.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1754
ALT-PU-2021-2955
CVE-2021-3195
OPENSUSE-SU-2022:0072-1
OPENSUSE-SU-2024:10654-1

Affected Products

Alt Linux
Bitcoin Core