Tag
high
advisory
Authorization Bypass in Klever-Go KleverUpdateAccountPermission Built-in
1 rule 7 TTPsAn authorization flaw in the Klever-Go VM allows attackers to execute an account takeover by leveraging an incorrectly validated RecipientAddr parameter during indirect smart contract calls.
klever-go +2
blockchain
smart-contract
vulnerability
privilege-escalation
log-manipulation
unauthenticated-access
websocket-vulnerability
consensus-failure
+6
1r
7t
updated
medium
threat
Klever-Go MultiDataInterceptor Remote OOM via Compressed Payload
2 rules 2 TTPsKlever-Go's MultiDataInterceptor is vulnerable to a remote denial-of-service (DoS) attack. By sending a crafted compressed P2P payload, an unauthenticated attacker can trigger excessive memory allocation on the receiving node, leading to an out-of-memory (OOM) condition and potentially disrupting chain liveness.
klever-go
denial-of-service
decompression-bomb
2r
2t