Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
ReDoS in eth-account encode_structured_data function
Vulnerability Description
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the eth-account PyPI package, when an attacker is able to supply arbitrary input to the encode_structured_data method
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
CWE-1333
Vulnerability Title
eth_account 安全漏洞
Vulnerability Description
eth_account是以太坊账号生成器。 eth_account 0.5.9之前版本存在安全漏洞,攻击者利用该漏洞可以在向 encode_structured_data 方法提供任意输入时,在 eth-account PyPI 包中触发指数 ReDoS。
CVSS Information
N/A
Vulnerability Type
N/A