BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale app is exposed. The sensitive information, found in the HTML source code, includes the xpub of the store. Also, if the store isn't using the internal lightning node, the credentials of a lightning node are exposed.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-01-31T00:00:00

Updated: 2023-01-31T00:00:00

Reserved: 2022-06-10T00:00:00


Link: CVE-2022-32984

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-01-31T22:15:08.000

Modified: 2023-02-08T22:22:38.523


Link: CVE-2022-32984

JSON object: View

cve-icon Redhat Information

No data.