According to Huoxing Finance, Bitcoin News posted on X that Alby has confirmed a critical vulnerability in Alby Hub versions v1.7.0 through v1.18.5; if the management API is exposed to the public internet, attackers could gain unauthorized access and transfer funds. One user is known to have been affected. Alby Hub v1.19.0 and later versions are not impacted. Alby advises affected users to restrict public internet access to the management interface, immediately upgrade to v1.24.0, and change their unlock password after updating. Multiple issues reported by Bitcoin Team Red, Project Loupe, and other researchers have also been fixed in the latest version.
Alby Hub v1.7.0 to v1.18.5 found with critical vulnerability exposing Management API
MarsBitShare
Versions v1.7.0 to v1.18.5 of Alby Hub were found to have a critical vulnerability that could expose the management API to unauthorized access. If exposed, attackers could transfer funds. One user is confirmed to have been affected. Alby recommends restricting public access and immediately updating to v1.24.0. The BTC update includes fixes provided by Bitcoin Team Red and Project Loupe. Alby Hub versions v1.19.0 and above are not affected. Users should also change their unlock passwords after updating.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.