Audit Open Original ↗
EthStaker Deposit CLI
Type
Security review
Client
EthStaker
Date
2024-12
Domain
Blockchain
Effort
4 wks
Section
Ethereum/EVM
Trail of Bits's security review of EthStaker (Dec 2024) identified 7 issues: 2 high, 2 medium, 1 low, and 2 informational.
Findings · 7
- 1 Use of unpinned third-party Docker image and actions on workflows Medium
- 2 Use of GPG for release signing and verification Informational
- 3 Sensitive files are incorrectly assigned permissions and ownership High
- 4 Error-prone path handling Informational
- 5 Emphasize critical warning regarding clipboard clearing Medium
- 6 Encryption function random parameters are set at program init High
- 7 Terminal bu er is not cleared on iTerm2 Low
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related