6.2

CVE-2016-8889

In Bitcoin Knots v0.11.0.ljr20150711 through v0.13.0.knots20160814 (fixed in v0.13.1.knots20161027), the debug console stores sensitive information including private keys and the wallet passphrase in its persistent command history.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bitcoin Knots Project ≫ Bitcoin Knots Version 0.11.0 Update rc1
Bitcoin Knots Project ≫ Bitcoin Knots Version 0.11.0 Update rc2
Bitcoin Knots Project ≫ Bitcoin Knots Version 0.11.0 Update rc3
Bitcoin Knots Project ≫ Bitcoin Knots Version 0.11.1 Update rc1
Bitcoin Knots Project ≫ Bitcoin Knots Version 0.11.1 Update rc2
Bitcoin Knots Project ≫ Bitcoin Knots Version 0.11.2 Update rc1
Bitcoin Knots Project ≫ Bitcoin Knots Version 0.12.0 Update rc1
Bitcoin Knots Project ≫ Bitcoin Knots Version 0.12.0 Update rc2
Bitcoin Knots Project ≫ Bitcoin Knots Version 0.12.0 Update rc3
Bitcoin Knots Project ≫ Bitcoin Knots Version 0.12.0 Update rc4
Bitcoin Knots Project ≫ Bitcoin Knots Version 0.12.0 Update rc5
Bitcoin Knots Project ≫ Bitcoin Knots Version 0.12.0.knots20160226 Update rc1
Bitcoin Knots Project ≫ Bitcoin Knots Version 0.12.1.knots20160629 Update rc2
Bitcoin Knots Project ≫ Bitcoin Knots Version 0.13.0.knots20160814
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.363
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.2 2.5 3.6
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://www.securityfocus.com/bid/94235
Third Party Advisory
VDB Entry
https://bitcointalk.org/index.php?topic=1618462.0
Third Party Advisory
Mitigation
https://github.com/bitcoinknots/bitcoin/blob/v0.13.1.knots20161027/doc/release-notes.md
Patch
Vendor Advisory