Arbitrary Data Injection Vulnerability in Bitcoin's bitcoind and Bitcoin-Qt
CVE-2018-20586

5.3MEDIUM

Key Information:

Vendor

Bitcoin

Vendor
CVE Published:
12 March 2020

What is CVE-2018-20586?

Prior to version 0.17.1, both bitcoind and Bitcoin-Qt allowed attackers to inject arbitrary data into the debug log through an RPC call. This vulnerability could potentially enable malicious actors to manipulate the log output, leading to unintended information disclosure or service disruption. It highlights the importance of securing RPC interfaces to prevent unauthorized data manipulation.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.