Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Famed Retroactive Rewards #25

Closed
Githubuser60 opened this issue Sep 21, 2022 · 2 comments
Closed

Famed Retroactive Rewards #25

Githubuser60 opened this issue Sep 21, 2022 · 2 comments
Assignees
Labels
famed Famed - Tracked by Famed high Famed - Common Vulnerability Scoring System (CVSS) - High

Comments

@Githubuser60
Copy link
Owner

UID: CL-2021-39

Severity: medium

Type: BUG

Affected Clients: Lighthouse

Summary: A validator client uses two API keys: ".secp-sk" (secret key) and "api-token.txt" (the corresponding public key).
Both files are stored in a user directory with 644 permission bits.
So any user on the host can read them.

Links: sigp/lighthouse#2437

Reported: 2021-07-07

Fixed: 2021-09-13

Published: 2021-12-01

Bounty Hunter: Taurus

Bounty Points: Part of EF initiated Security Audit: https://arxiv.org/abs/2109.11685

@Githubuser60 Githubuser60 added high Famed - Common Vulnerability Scoring System (CVSS) - High famed Famed - Tracked by Famed labels Sep 21, 2022
@Githubuser60 Githubuser60 self-assigned this Sep 21, 2022
@x0r-ai
Copy link

x0r-ai bot commented Sep 21, 2022

🤖 Assignees for issue Famed Retroactive Rewards #25 are now eligible to Get Famed.

✅ Add assignees to track contribution times of the issue 🦸‍♀️🦹️
✅ Add a single severity (CVSS) label to compute the score 🏷️️

Happy hacking! 🦾💙❤️️

@x0r-ai
Copy link

x0r-ai bot commented Sep 21, 2022

@Githubuser60 - you Got Famed! 💎 Check out your new score here: https://leaderboard.morphysm.com/teams/Githubuser60/famed-demo

Contributor Time Reward
Githubuser60 1632h0m0s 2444 POINTS

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
famed Famed - Tracked by Famed high Famed - Common Vulnerability Scoring System (CVSS) - High
Projects
None yet
Development

No branches or pull requests

1 participant