CVE-2018-1000022
Electrum Technologies GmbH Electrum Bitcoin Wallet version prior to version 3.0.5 contains a Missing Authorization vulnerability in JSONRPC interface that can result in Bitcoin theft, if the user's wallet is not password protected.
Does this matter?
Lower severity and a low EPSS score (1.74%). Track it; it rarely justifies an emergency change on its own.
Description
Electrum Technologies GmbH Electrum Bitcoin Wallet version prior to version 3.0.5 contains a Missing Authorization vulnerability in JSONRPC interface that can result in Bitcoin theft, if the user's wallet is not password protected. This attack appear to be exploitable via The victim must visit a web page with specially crafted javascript. This vulnerability appears to have been fixed in 3.0.5.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 1.74% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- electrum/bitcoin wallet
- Source
- cve@mitre.org
References
- https://bitcointalk.org/index.php?topic=2702103.0Third Party Advisory
- https://electrum.org/#homeProduct
- https://github.com/spesmilo/electrum/issues/3374Third Party Advisory
- https://www.reddit.com/r/Bitcoin/comments/7ooack/critical_electrum_vulnerability/Third Party Advisory
- https://bitcointalk.org/index.php?topic=2702103.0Third Party Advisory
- https://electrum.org/#homeProduct
- https://github.com/spesmilo/electrum/issues/3374Third Party Advisory
- https://www.reddit.com/r/Bitcoin/comments/7ooack/critical_electrum_vulnerability/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.