CVE-2018-15890: Critical severity ethereum vulnerability
Published Jun 20, 2019
·Updated
An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and decoder.readObject in crypto/ECKey.java. When a node syncs and mines a new block, arbitrary OS commands can be run on the server.
Affected Software
1 affected component
Ethereum EthereumJ=1.8.2
Event History
Jun 20, 2019
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-15890?
CVE-2018-15890 is a vulnerability in EthereumJ 1.8.2 that allows arbitrary OS commands to be run on the server.
2
How severe is CVE-2018-15890?
CVE-2018-15890 has a severity rating of 9.8 (Critical).
3
What software versions are affected by CVE-2018-15890?
CVE-2018-15890 affects EthereumJ version 1.8.2.
4
How can I fix CVE-2018-15890?
To fix CVE-2018-15890, it is recommended to update EthereumJ to a version that contains a fix for the vulnerability.
5
Where can I find more information about CVE-2018-15890?
You can find more information about CVE-2018-15890 on the official GitHub repository of EthereumJ.