VYPR
Unrated severityOSV Advisory· Published Jun 5, 2018· Updated Aug 5, 2024

CVE-2018-10057

CVE-2018-10057

Description

The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to write the miner configuration file to arbitrary locations on the server due to missing basedir restrictions (absolute directory traversal).

Affected products

1
  • Range: bfgminer-2.10.0, bfgminer-2.10.1, bfgminer-2.10.2, …

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.