SB2018082807 - Information disclosure in EOS
Published: August 28, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Information disclosure (CVE-ID: N/A)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The weakness exists due to unspecified flaw. A remote attacker can install code on his account, insert large amounts of garbage into rows when dapps/users send the tokens, lock up RAM and steal web resources from the victims' accounts with no authentication.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.