
Cloud Vulnerability DB
A community-led vulnerabilities database
bitcoind and Bitcoin-Qt prior to 0.17.1 allow injection of arbitrary data into the debug log via an RPC call (NVD, Bitcoin Wiki). The vulnerability was discovered in 2019 and affects Bitcoin Core and Bitcoin-Qt versions before 0.17.1.
The vulnerability is classified as a deception-type flaw that allows debug log injection through unauthenticated RPC access. It has been assigned a CVSS v3.1 Base Score of 5.3 (MEDIUM) with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N, and a CVSS v2.0 Base Score of 4.3 (MEDIUM) with vector (AV:N/AC:M/Au:N/C:N/I:P/A:N) (NVD).
The vulnerability allows attackers to inject arbitrary data into the debug log of the Bitcoin client. While this does not directly compromise the security of funds or the network, it could potentially be used for deception or social engineering attacks by manipulating log entries (Bitcoin Wiki).
The vulnerability was fixed in Bitcoin Core and Bitcoin-Qt version 0.17.1. Users running affected versions should upgrade to version 0.17.1 or later to mitigate this vulnerability (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."