CVE-2017-12118: High severity ethereum blockchain vulnerability
Published Jan 19, 2018
·Updated
An exploitable improper authorization vulnerability exists in minerstop API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). An attacker can send JSON to trigger this vulnerability.
Affected Software
1 affected component
Ethereum cpp-ethereum
Event History
Jan 19, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-12118.
2
What is the severity of CVE-2017-12118?
The severity of CVE-2017-12118 is high with a CVSS score of 8.1.
3
What software is affected by CVE-2017-12118?
The software affected by CVE-2017-12118 is Ethereum Cpp-ethereum.
4
What is the description of CVE-2017-12118?
CVE-2017-12118 is an improper authorization vulnerability in the miner_stop API of cpp-ethereum's JSON-RPC.
5
How can an attacker exploit CVE-2017-12118?
An attacker can send JSON to trigger the vulnerability.