bitcoind in Bitcoin Core through 0.21.0 can create a new file in an arbitrary directory (e.g., outside the ~/.bitcoin directory) via a dumpwallet RPC call. NOTE: this reportedly does not violate the security model of Bitcoin Core, but can violate the security model of a fork that has implemented dumpwallet restrictions
References
Link | Resource |
---|---|
https://github.com/bitcoin/bitcoin/issues/20866 | Exploit Issue Tracking Third Party Advisory |
Configurations
History
07 Nov 2023, 03:37
Type | Values Removed | Values Added |
---|---|---|
Summary | bitcoind in Bitcoin Core through 0.21.0 can create a new file in an arbitrary directory (e.g., outside the ~/.bitcoin directory) via a dumpwallet RPC call. NOTE: this reportedly does not violate the security model of Bitcoin Core, but can violate the security model of a fork that has implemented dumpwallet restrictions |
08 Mar 2021, 13:26
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://github.com/bitcoin/bitcoin/issues/20866 - Exploit, Issue Tracking, Third Party Advisory |
17 Feb 2021, 23:15
Type | Values Removed | Values Added |
---|---|---|
Summary | ** DISPUTED ** bitcoind in Bitcoin Core through 0.21.0 can create a new file in an arbitrary directory (e.g., outside the ~/.bitcoin directory) via a dumpwallet RPC call. NOTE: this reportedly does not violate the security model of Bitcoin Core, but can violate the security model of a fork that has implemented dumpwallet restrictions. |
02 Feb 2021, 16:09
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 5.0
v3 : 7.5 |
References | (MISC) https://github.com/bitcoin/bitcoin/issues/20866 - Third Party Advisory | |
CPE | cpe:2.3:a:bitcoin:bitcoin_core:*:*:*:*:*:*:*:* | |
CWE | CWE-20 |
26 Jan 2021, 18:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-01-26 18:16
Updated : 2024-05-17 02:00
NVD link : CVE-2021-3195
Mitre link : CVE-2021-3195
CVE.ORG link : CVE-2021-3195
JSON object : View
Products Affected
bitcoin
- bitcoin_core
CWE
CWE-20
Improper Input Validation