CVE-2017-12117: High severity ethereum blockchain vulnerability
An exploitable improper authorization vulnerability exists in minerstart API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the restricted functionality resulting in authorization bypass. An attacker can send JSON to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2017-12117.
How severe is CVE-2017-12117?
CVE-2017-12117 has a severity rating of 8.1 (High).
What is the affected software for CVE-2017-12117?
The affected software for CVE-2017-12117 is Ethereum Cpp-ethereum.
How can an attacker exploit CVE-2017-12117?
An attacker can exploit CVE-2017-12117 by sending a crafted JSON request to the miner_start API of cpp-ethereum's JSON-RPC, causing an access to restricted functionality and bypassing authorization.
Are there any references for CVE-2017-12117?
Yes, you can find references for CVE-2017-12117 at the following links: [http://www.securityfocus.com/bid/102475](http://www.securityfocus.com/bid/102475) and [https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0469](https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0469).