CVE-2017-12115: High severity Ethereum cpp-ethereum vulnerability
An exploitable improper authorization vulnerability exists in minersetEtherbase API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the restricted functionality resulting in authorization bypass.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-12115?
CVE-2017-12115 is an exploitable improper authorization vulnerability in miner_setEtherbase API of cpp-ethereum's JSON-RPC.
What is the severity of CVE-2017-12115?
The severity of CVE-2017-12115 is high, with a severity value of 8.1.
How can CVE-2017-12115 be exploited?
CVE-2017-12115 can be exploited by sending a malicious JSON request to the miner_setEtherbase API, which can bypass authorization and access restricted functionality.
What software is affected by CVE-2017-12115?
Cpp-ethereum version cpe:2.3:a:ethereum:cpp-ethereum is affected by CVE-2017-12115.
Where can I find more information about CVE-2017-12115?
You can find more information about CVE-2017-12115 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/102475) and [Talos Intelligence](https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0467).