First published: Fri Mar 26 2021(Updated: )
BTCPay Server before 1.0.6.0, when the payment button is used, has a privacy vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BTCPayServer | <1.0.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29249 is classified as a privacy vulnerability affecting BTCPay Server versions before 1.0.6.0.
To fix CVE-2021-29249, upgrade your BTCPay Server to version 1.0.6.0 or later.
CVE-2021-29249 can lead to unauthorized exposure of user payment information.
CVE-2021-29249 affects all versions of BTCPay Server prior to 1.0.6.0.
There is no known workaround for CVE-2021-29249; upgrading is the recommended solution.