CVE-2017-12114: Medium severity ethereum blockchain vulnerability
An exploitable improper authorization vulnerability exists in adminpeers API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the restricted functionality resulting in authorization bypass. An attacker can send JSON to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2017-12114.
What is the title of the vulnerability?
The title of the vulnerability is 'An exploitable improper authorization vulnerability exists in admin_peers API of cpp-ethereum's JSON-RPC'.
What is the severity of CVE-2017-12114?
The severity of CVE-2017-12114 is medium with a severity value of 6.8.
Which software is affected by CVE-2017-12114?
The software affected by CVE-2017-12114 is Ethereum Cpp-ethereum.
How can an attacker exploit CVE-2017-12114?
An attacker can exploit CVE-2017-12114 by sending a malicious JSON request to the admin_peers API of cpp-ethereum's JSON-RPC, which can result in an authorization bypass.