Vulnerability Details CVE-2018-1000023
Bitpay/insight-api Insight-api version 5.0.0 and earlier contains a CWE-20: input validation vulnerability in transaction broadcast endpoint that can result in Full Path Disclosure. This attack appear to be exploitable via Web request.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 46.0%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2018-1000023
-
cpe:2.3:a:insight.bitpay:insight-api:0.1.10
-
cpe:2.3:a:insight.bitpay:insight-api:0.1.12
-
cpe:2.3:a:insight.bitpay:insight-api:0.2.1
-
cpe:2.3:a:insight.bitpay:insight-api:0.2.2
-
cpe:2.3:a:insight.bitpay:insight-api:0.2.5
-
cpe:2.3:a:insight.bitpay:insight-api:0.4.0
-
cpe:2.3:a:insight.bitpay:insight-api:5.0.0