CVE-2018-1000022

EUVD-2018-1785
Electrum Technologies GmbH Electrum Bitcoin Wallet version prior to version 3.0.5 contains a Missing Authorization vulnerability in JSONRPC interface that can result in Bitcoin theft, if the user's wallet is not password protected. This attack appear to be exploitable via The victim must visit a web page with specially crafted javascript. This vulnerability appears to have been fixed in 3.0.5.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 36%
Affected Products (NVD)
VendorProductVersion
electrumbitcoin_wallet
𝑥
< 3.0.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
electrum
bookworm
4.3.4+dfsg1-1+deb12u1
fixed
bullseye
4.0.9-1
fixed
jessie
not-affected
sid
4.5.8+ds-2
fixed
trixie
4.5.8+ds-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
electrum
artful
dne
bionic
dne
cosmic
dne
disco
dne
trusty
dne
xenial
dne