CVE-2018-1000022

Electrum Technologies GmbH Electrum Bitcoin Wallet version prior to version 3.0.5 contains a Missing Authorization vulnerability in JSONRPC interface that can result in Bitcoin theft, if the user's wallet is not password protected. This attack appear to be exploitable via The victim must visit a web page with specially crafted javascript. This vulnerability appears to have been fixed in 3.0.5.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
VendorProductVersion
electrumbitcoin_wallet
𝑥
< 3.0.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
electrum
bullseye
4.0.9-1
fixed
jessie
not-affected
bookworm
4.3.4+dfsg1-1+deb12u1
fixed
trixie
4.5.8+ds-1
fixed
sid
4.5.8+ds-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
electrum
disco
dne
cosmic
dne
bionic
dne
artful
dne
xenial
dne
trusty
dne