Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An exploitable overly permissive cross-domain (CORS) whitelist vulnerability exists in JSON-RPC of Parity Ethereum client version 1.7.8. An automatically sent JSON object to JSON-RPC endpoint can trigger this vulnerability. A victim needs to visit a malicious website to trigger this vulnerability.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Parity Ethereum client JSON-RPC 安全漏洞
Vulnerability Description
Parity Ethereum client是Ethereum(应用程序运行平台)的客户端。JSON-RPC是其中的一个以JSON为协议的远程调用服务。 Parity Ethereum client 1.7.8版本中的JSON-RPC存在安全漏洞。攻击者可利用该漏洞向JSON-RPC端点发送JSON对象利用该漏洞获取当前账户、parity设置和网络配置的信息,也可更改账户和parity的配置。
CVSS Information
N/A
Vulnerability Type
N/A