Arbitrary Data Injection Vulnerability in Bitcoin's bitcoind and Bitcoin-Qt
CVE-2018-20586
5.3MEDIUM
What is CVE-2018-20586?
Prior to version 0.17.1, both bitcoind and Bitcoin-Qt allowed attackers to inject arbitrary data into the debug log through an RPC call. This vulnerability could potentially enable malicious actors to manipulate the log output, leading to unintended information disclosure or service disruption. It highlights the importance of securing RPC interfaces to prevent unauthorized data manipulation.