Vulnerabilities (CVE)

Filtered by vendor Ethereum Subscribe
Filtered by product Aleth
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-12116 1 Ethereum 1 Aleth 2021-01-19 6.8 MEDIUM 8.1 HIGH
An exploitable improper authorization vulnerability exists in miner_setGasPrice API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the restricted functionality resulting in authorization bypass. An attacker can send JSON to trigger this vulnerability.