6.2
CVE-2016-8889
- EPSS 0.09%
- Veröffentlicht 28.10.2016 15:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
In Bitcoin Knots v0.11.0.ljr20150711 through v0.13.0.knots20160814 (fixed in v0.13.1.knots20161027), the debug console stores sensitive information including private keys and the wallet passphrase in its persistent command history.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bitcoin Knots Project ≫ Bitcoin Knots Version0.11.0
Bitcoin Knots Project ≫ Bitcoin Knots Version0.11.0 Updaterc1
Bitcoin Knots Project ≫ Bitcoin Knots Version0.11.0 Updaterc2
Bitcoin Knots Project ≫ Bitcoin Knots Version0.11.0 Updaterc3
Bitcoin Knots Project ≫ Bitcoin Knots Version0.11.1
Bitcoin Knots Project ≫ Bitcoin Knots Version0.11.1 Updaterc1
Bitcoin Knots Project ≫ Bitcoin Knots Version0.11.1 Updaterc2
Bitcoin Knots Project ≫ Bitcoin Knots Version0.11.2
Bitcoin Knots Project ≫ Bitcoin Knots Version0.11.2 Updaterc1
Bitcoin Knots Project ≫ Bitcoin Knots Version0.12.0
Bitcoin Knots Project ≫ Bitcoin Knots Version0.12.0 Updaterc1
Bitcoin Knots Project ≫ Bitcoin Knots Version0.12.0 Updaterc2
Bitcoin Knots Project ≫ Bitcoin Knots Version0.12.0 Updaterc3
Bitcoin Knots Project ≫ Bitcoin Knots Version0.12.0 Updaterc4
Bitcoin Knots Project ≫ Bitcoin Knots Version0.12.0 Updaterc5
Bitcoin Knots Project ≫ Bitcoin Knots Version0.12.0.knots20160226 Updaterc1
Bitcoin Knots Project ≫ Bitcoin Knots Version0.12.1.knots20160629 Updaterc2
Bitcoin Knots Project ≫ Bitcoin Knots Version0.13.0.knots20160814
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.09% | 0.219 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.2 | 2.5 | 3.6 |
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.