Medium severity5.5OSV Advisory· Published Feb 11, 2019· Updated Jun 17, 2026
CVE-2018-20587
CVE-2018-20587
Description
Bitcoin Core 0.12.0 through 0.17.1 and Bitcoin Knots 0.12.0 through 0.17.x before 0.17.1.knots20181229 have Incorrect Access Control. Local users can exploit this to steal currency by binding the RPC IPv4 localhost port, and forwarding requests to the IPv6 localhost port.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7(expand)+ 2 more
- (no CPE)
- cpe:2.3:a:bitcoin:bitcoin_core:*:*:*:*:*:*:*:*range: >=0.12.0,<=0.17.1
- (no CPE)range: 0.12.0 - 0.17.1
- cpe:2.3:a:bitcoinknots:bitcoin_knots:*:*:*:*:*:*:*:*Range: >=0.12.0,<=0.17.0
- Range: 0.12.0 - 0.17.x before 0.17.1.knots20181229
- osv-coords2 versionspkg:rpm/opensuse/bitcoin&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/bitcoin&distro=openSUSE%20Tumbleweed
< 27.1-bp160.2.1+ 1 more
- (no CPE)range: < 27.1-bp160.2.1
- (no CPE)range: < 31.0-2.1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.