CVE-2022-32984: Infoleak
BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale app is exposed. The sensitive information, found in the HTML source code, includes the xpub of the store. Also, if the store isn't using the internal lightning node, the credentials of a lightning node are exposed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-32984?
The severity of CVE-2022-32984 is high with a severity value of 7.5.
What is affected by CVE-2022-32984?
BTCPay Server versions 1.3.0 through 1.5.3 are affected by CVE-2022-32984.
How does CVE-2022-32984 allow a remote attacker to obtain sensitive information?
CVE-2022-32984 allows a remote attacker to obtain sensitive information by accessing the HTML source code of a public Point of Sale app exposed by BTCPay Server.
What sensitive information can be obtained by exploiting CVE-2022-32984?
The sensitive information that can be obtained includes the xpub (extended public key) of the store and, if applicable, the credentials for the internal lightning node.
Is there a fix available for CVE-2022-32984?
Yes, users should upgrade to a version of BTCPay Server that is not affected by CVE-2022-32984, such as version 1.5.4 or higher.