CVE-2017-12113: High severity Ethereum cpp-ethereum vulnerability
An exploitable improper authorization vulnerability exists in adminnodeInfo API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the restricted functionality resulting in authorization bypass. An attacker can send JSON to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-12113?
CVE-2017-12113 is an exploitable improper authorization vulnerability that exists in the admin_nodeInfo API of cpp-ethereum's JSON-RPC.
What is the severity of CVE-2017-12113?
The severity of CVE-2017-12113 is high with a severity value of 8.1.
How can an attacker exploit CVE-2017-12113?
An attacker can send a malicious JSON request to trigger the vulnerability, which can cause an access to restricted functionality and result in an authorization bypass.
What software is affected by CVE-2017-12113?
The Ethereum Cpp-ethereum software is affected by CVE-2017-12113.
How can CVE-2017-12113 be fixed?
To fix CVE-2017-12113, it is recommended to update to a version that contains the fix provided by the software vendor.