CVE-2024-34694

LNbits is a Lightning wallet and accounts system. Paying invoices in Eclair that do not get settled within the internal timeout (about 30s) lead to a payment being considered failed, even though it may still be in flight. This vulnerability can lead to a total loss of funds for the node backend. This vulnerability is fixed in 0.12.6.
Configurations

No configuration.

History

17 Jun 2024, 12:42

Type Values Removed Values Added
Summary
  • (es) LNbits es un sistema de cuentas y billetera Lightning. Pagar facturas en Eclair que no se liquidan dentro del tiempo de espera interno (alrededor de 30 segundos) hace que el pago se considere fallido, aunque todavía pueda estar en proceso. Esta vulnerabilidad puede provocar una pérdida total de fondos para el backend del nodo. Esta vulnerabilidad se solucionó en 0.12.6.

14 Jun 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-14 15:15

Updated : 2024-06-17 12:42


NVD link : CVE-2024-34694

Mitre link : CVE-2024-34694

CVE.ORG link : CVE-2024-34694


JSON object : View

Products Affected

No product.

CWE
CWE-754

Improper Check for Unusual or Exceptional Conditions