CVE-2022-32984 is a sensitive information disclosure vulnerability affecting BTCPay Server versions 1.3.0 through 1.5.3. A remote attacker can obtain the store's xpub and, if not using the internal lightning node, lightning node credentials from the HTML source of a publicly exposed Point of Sale app. This vulnerability has a CVSS score of 7.5 (High) due to its network attack vector, low complexity, and high confidentiality impact. There is no evidence of active exploitation, public exploit code, or significant community discussion, with only one article mentioning it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.3.0, <= 1.5.3CPE matchmatch criteria | cpe:2.3:a:btcpayserver:btcpay_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.