CVE-2023-50475: Critical severity bcoin vulnerability
An issue was discovered in bcoin-org bcoin version 2.2.0, allows remote attackers to obtain sensitive information via weak hashing algorithms in the component \vendor\faye-websocket.js.
Other sources
An issue was discovered in the bsock component of bcoin-org bcoin that allows remote attackers to obtain sensitive information via weak hashing algorithms in the component \vendor\faye-websocket.js.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50475?
CVE-2023-50475 has been classified as a medium severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2023-50475?
To fix CVE-2023-50475, update the bcoin package to version 2.2.1 or later to mitigate the vulnerability.
What components are affected by CVE-2023-50475?
CVE-2023-50475 affects the bcoin version 2.2.0 and the bsock package version up to 0.1.11.
What kind of attack does CVE-2023-50475 enable?
CVE-2023-50475 enables remote attackers to obtain sensitive information via weak hashing algorithms.
Which hashing algorithms are considered weak in CVE-2023-50475?
CVE-2023-50475 concerns the use of weak hashing algorithms in the vendor component faye-websocket.js.