cryptoadvance.specter@1.2.1 vulnerabilities
A GUI for Bitcoin Core & Electrum optimised to work with airgapped hardware wallets
-
latest version
2.0.5
-
latest non vulnerable version
-
first published
5 years ago
-
latest version published
6 months ago
-
licenses detected
- [0,)
Direct Vulnerabilities
Known vulnerabilities in the cryptoadvance.specter package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
cryptoadvance.specter is an A GUI for Bitcoin Core & Electrum optimised to work with airgapped hardware wallets Affected versions of this package are vulnerable to Open Redirect where the "next" parameter during the login process on Specter desktop can be manipulated to redirect users to an unauthorized domain after login. This vulnerability poses a phishing risk, as attackers can easily direct users to malicious sites by altering the "next" parameter in the URL. How to fix Open Redirect? Upgrade |
[,2.0.2)
|
cryptoadvance.specter is an A GUI for Bitcoin Core & Electrum optimised to work with airgapped hardware wallets Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) when How to fix Cross-site Request Forgery (CSRF)? Upgrade |
[,1.7.2)
|