SB20231212114 - Multiple vulnerabilities in Bitcoin Knots
Published: December 12, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Security features bypass (CVE-ID: CVE-2023-40257)
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to an unspecified error in the extended rpcauth wallet-restriction syntax, which is intended to enable semi-trusted local applications using the Bitcoin Knots API to access only specific wallets and not others. A local user can bypass implemented security restrictions.
2) Security features bypass (CVE-ID: CVE-2023-40258)
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to an unspecified error in the extended rpcauth wallet-restriction syntax, which is intended to enable semi-trusted local applications using the Bitcoin Knots API to access only specific wallets and not others. A local user can bypass implemented security restrictions.
3) Security features bypass (CVE-ID: CVE-2023-40259)
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to an unspecified error in the extended rpcauth wallet-restriction syntax, which is intended to enable semi-trusted local applications using the Bitcoin Knots API to access only specific wallets and not others. A local user can bypass implemented security restrictions.
Remediation
Install update from vendor's website.