VulnerabilityModified
CVE-2016-8889
In Bitcoin Knots v0.11.0.ljr20150711 through v0.13.0.knots20160814 (fixed in v0.13.1.knots20161027), the debug console stores sensitive information including private keys and the wallet passphrase in its persistent command history.
MEDIUM 6.2EPSS 0.46%
Does this matter?
Lower severity and a low EPSS score (0.46%). Track it; it rarely justifies an emergency change on its own.
Description
In Bitcoin Knots v0.11.0.ljr20150711 through v0.13.0.knots20160814 (fixed in v0.13.1.knots20161027), the debug console stores sensitive information including private keys and the wallet passphrase in its persistent command history.
- CVSS 3.0
- 6.2 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.46% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-310
- Affected
- bitcoin knots project/bitcoin knots
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/94235Third Party Advisory, VDB Entry
- https://bitcointalk.org/index.php?topic=1618462.0Mitigation, Third Party Advisory
- https://github.com/bitcoinknots/bitcoin/blob/v0.13.1.knots20161027/doc/release-notes.mdPatch, Vendor Advisory
- http://www.securityfocus.com/bid/94235Third Party Advisory, VDB Entry
- https://bitcointalk.org/index.php?topic=1618462.0Mitigation, Third Party Advisory
- https://github.com/bitcoinknots/bitcoin/blob/v0.13.1.knots20161027/doc/release-notes.mdPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.