CVE-2021-29249: High severity btcpayserver vulnerability
Published Mar 26, 2021
·Updated
BTCPay Server before 1.0.6.0, when the payment button is used, has a privacy vulnerability.
Affected Software
1 affected component
btcpayserver Btcpay Server<1.0.6.0
Event History
Mar 26, 2021
CVE Published
via MITRE·10:20 PM
Data Sourced
via MITRE·10:20 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-29249?
CVE-2021-29249 is classified as a privacy vulnerability affecting BTCPay Server versions before 1.0.6.0.
2
How do I fix CVE-2021-29249?
To fix CVE-2021-29249, upgrade your BTCPay Server to version 1.0.6.0 or later.
3
What are the potential impacts of CVE-2021-29249?
CVE-2021-29249 can lead to unauthorized exposure of user payment information.
4
Which versions are affected by CVE-2021-29249?
CVE-2021-29249 affects all versions of BTCPay Server prior to 1.0.6.0.
5
Is there a workaround for CVE-2021-29249?
There is no known workaround for CVE-2021-29249; upgrading is the recommended solution.