rpcserver: Ensure limited user is always limited
Fixed in: dcrd v2.1.4 (release-v2.1.4)
details
- Finding IDs
- F-DECRED-DCRD-RPC-LIMITED-ONLY-001
- Status
- fixed publicly
- Fixed in
- dcrd v2.1.4 (release-v2.1.4)
- Reported via
- security contact
- Note
- public master fix commit 2d6b77049f1c on 2026-03-10. the official dcrd release-v2.1.4 notes, published on 2026-04-07, include the limited-user authentication fix via PR #3660: https://github.com/decred/dcrd/releases/tag/release-v2.1.4. this corrects the previously recorded v1.10.6 version; v2.1.4 is a verified release containing the fix, not a claim about the earliest fixed version on every branch. the change prevents limited-only access from gaining administrator privileges when admin auth is unset.
F-DECRED-DCRD-RPC-LIMITED-ONLY-001: Access control. Limited RPC credentials cross the intended method-permission boundary. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-DECRED-DCRD-RPC-LIMITED-ONLY-001
Security area (1seal assessment): Authorization. A limited RPC account must not gain administrator access when administrator credentials are unset. Reviewed 21 Sep 2026.