Insight API transaction broadcast endpoint can result in Full Path Disclosure
Moderate severity
GitHub Reviewed
Published
Mar 5, 2018
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Published to the GitHub Advisory Database
Mar 5, 2018
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
Bitpay/insight-api Insight-api version 5.0.0 and earlier contains a CWE-20: input validation vulnerability in transaction broadcast endpoint that can result in Full Path Disclosure. This attack appear to be exploitable via Web request.
References