PyPi: Chia-Blockchain

CVE-2023-3728

Transitive

Safety vulnerability ID: 64108

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Aug 01, 2023 Updated at Dec 12, 2024
Scan your Python projects for vulnerabilities →

Advisory

Chia-blockchain 2.0.0rc4 updates its NPM dependency 'Electron' to 25.4.0 to include security fixes.
https://github.com/Chia-Network/chia-blockchain-gui/pull/1976

Affected package

chia-blockchain

Latest version: 2.5.0

Chia blockchain full node, farmer, timelord, and wallet.

Affected versions

Fixed versions

Vulnerability changelog

<details>
<!-- Release notes generated using configuration in .github/release.yml at release/2.0.0 -->

<summary>

What's Changed

Due to the number of changes that have been made, it is *highly* encouraged that you generate a new `config.yaml` (`chia init`) before using this build. Please remember to also do this on remote harvesters/farmers as well.

</summary>

Changed
* Revert "Add fields to BlockRecord. (15695)" by arvidn in https://github.com/Chia-Network/chia-blockchain/pull/15947
* Update chia_rs to 0.2.10 by emlowe in https://github.com/Chia-Network/chia-blockchain/pull/15973
* Bladebit3 as the default plotter to install by ChiaMineJP in https://github.com/Chia-Network/chia-blockchain/pull/15943

Fixed
* Fixed an issue where `-t` option was required in cudaplot by ChiaMineJP in https://github.com/Chia-Network/chia-blockchain/pull/15963
* Add ALLOW_BACKREFS as a flag to get_puzzle_and_solution_for_coin in full_node_api.py by Quexington in https://github.com/Chia-Network/chia-blockchain/pull/15937
* Fix clawback sender resync issue by ytx1991 in https://github.com/Chia-Network/chia-blockchain/pull/15853

GUI Changes
* Use lerna 7.1.3 and nx 16.3.2 for macos 10.14 building by emlowe in https://github.com/Chia-Network/chia-blockchain-gui/pull/1917
* Fix "From" to "To" in wallet history by zsolt-dev in https://github.com/Chia-Network/chia-blockchain-gui/pull/1939
* Hide harvester tab in setting page in wallet mode by ChiaMineJP in https://github.com/Chia-Network/chia-blockchain-gui/pull/1941
* Update "Clawback will be applied." warning by zsolt-dev in https://github.com/Chia-Network/chia-blockchain-gui/pull/1940
* Fixed add plot page by ChiaMineJP in https://github.com/Chia-Network/chia-blockchain-gui/pull/1954
* Add clawBackExpiration behind the expand TX row for clawback sender by zsolt-dev in https://github.com/Chia-Network/chia-blockchain-gui/pull/1950
* Hide clawback TXs while wallet is syncing by zsolt-dev in https://github.com/Chia-Network/chia-blockchain-gui/pull/1951
* Updated harvester setting page by ChiaMineJP in https://github.com/Chia-Network/chia-blockchain-gui/pull/1949
* Design fixes to Address Book by lipalong in https://github.com/Chia-Network/chia-blockchain-gui/pull/1957
* Hide GPU setting when it is not available by ChiaMineJP in https://github.com/Chia-Network/chia-blockchain-gui/pull/1959
* `start_plotting` fix by ChiaMineJP in https://github.com/Chia-Network/chia-blockchain-gui/pull/1958
* Icon updates by paninaro in https://github.com/Chia-Network/chia-blockchain-gui/pull/1967
* The label of `last block won` is now `Never` when there are no blocks… by ChiaMineJP in https://github.com/Chia-Network/chia-blockchain-gui/pull/1971
* Hide temp folder selection on cudaplot by ChiaMineJP in https://github.com/Chia-Network/chia-blockchain-gui/pull/1972
* Update Electron to 25.4.0 for security fixes by paninaro in https://github.com/Chia-Network/chia-blockchain-gui/pull/1976
* Plot filter value now is the function of height by ChiaMineJP in https://github.com/Chia-Network/chia-blockchain-gui/pull/1979
* Fixed inconsistent step count by ChiaMineJP in https://github.com/Chia-Network/chia-blockchain-gui/pull/1986
* Added compressed plot size texts by ChiaMineJP in https://github.com/Chia-Network/chia-blockchain-gui/pull/1987


**Full Changelog**: https://github.com/Chia-Network/chia-blockchain/compare/2.0.0-rc3...2.0.0-rc4
</details>

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

HIGH 8.8

CVSS v3 Details

HIGH 8.8
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
REQUIRED
Scope (S)
UNCHANGED
Confidentiality Impact (C)
HIGH
Integrity Impact (I)
HIGH
Availability Availability (A)
HIGH