Copay Bitcoin Wallet version 5.01 to 5.1.0 included. contains a Other/Unknown vulnerability in wallet private key storage that can result in Users' private key can be compromised. . This attack appear to be exploitable via Affected version run the malicious code at startup . This vulnerability appears to have been fixed in 5.2.0 and later .
References
Link | Resource |
---|---|
https://arstechnica.com/information-technology/2018/11/hacker-backdoors-widely-used-open-source-software-to-steal-bitcoin/ | Third Party Advisory |
https://blog.bitpay.com/npm-package-vulnerability-copay/ | Third Party Advisory |
https://github.com/bitpay/copay/issues/9346 | Exploit Issue Tracking Patch Third Party Advisory |
https://github.com/dominictarr/event-stream/issues/116 | Exploit Issue Tracking Patch Third Party Advisory |
Configurations
History
No history.
Information
Published : 2018-12-20 15:29
Updated : 2024-02-04 20:03
NVD link : CVE-2018-1000851
Mitre link : CVE-2018-1000851
CVE.ORG link : CVE-2018-1000851
JSON object : View
Products Affected
copay
- copay_bitcoin_wallet
CWE
CWE-522
Insufficiently Protected Credentials