Skip to content

Insight API transaction broadcast endpoint can result in Full Path Disclosure

Moderate severity GitHub Reviewed Published Mar 5, 2018 to the GitHub Advisory Database • Updated Jan 9, 2023

Package

npm insight-api (npm)

Affected versions

<= 5.0.0

Patched versions

None

Description

Bitpay/insight-api Insight-api version 5.0.0 and earlier contains a CWE-20: input validation vulnerability in transaction broadcast endpoint that can result in Full Path Disclosure. This attack appear to be exploitable via Web request.

References

Published to the GitHub Advisory Database Mar 5, 2018
Reviewed Jun 16, 2020
Last updated Jan 9, 2023

Severity

Moderate
5.3
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Weaknesses

CVE ID

CVE-2018-1000023

GHSA ID

GHSA-8p2p-p8mg-x3cw

Source code

Checking history
See something to contribute? Suggest improvements for this vulnerability.