CVE-2021-29251: Medium severity btcpayserver vulnerability
Published Apr 1, 2021
·Updated
BTCPay Server before 1.0.7.1 mishandles the policy setting in which users can register (in Server Settings > Policies). This affects Docker use cases in which a mail server is configured.
Affected Software
1 affected component
btcpayserver Btcpay Server<1.0.7.1
Event History
Apr 1, 2021
CVE Published
via MITRE·04:42 AM
Data Sourced
via MITRE·04:42 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-29251?
CVE-2021-29251 is classified as a medium-severity vulnerability due to its potential impact on user registration policies.
2
How do I fix CVE-2021-29251?
To fix CVE-2021-29251, upgrade your BTCPay Server to version 1.0.7.1 or later.
3
Which versions of BTCPay Server are affected by CVE-2021-29251?
CVE-2021-29251 affects BTCPay Server versions prior to 1.0.7.1.
4
What is the impact of CVE-2021-29251?
The impact of CVE-2021-29251 involves mishandling of user registration policies, potentially allowing unauthorized access in Docker configurations.
5
Is CVE-2021-29251 specific to Docker deployments of BTCPay Server?
Yes, CVE-2021-29251 specifically affects Docker use cases where a mail server is configured.