CVE-2024-32873

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. The spendable balance is not updated properly when delegating vested tokens. The issue allows a clawback vesting account to anticipate the release of unvested tokens. This vulnerability is fixed in 18.0.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:evmos:evmos:*:*:*:*:*:*:*:*

History

15 Oct 2024, 19:22

Type Values Removed Values Added
First Time Evmos
Evmos evmos
References () https://github.com/evmos/evmos/commit/b2a09ca66613d8b04decd3f2dcba8e1e77709dcb - () https://github.com/evmos/evmos/commit/b2a09ca66613d8b04decd3f2dcba8e1e77709dcb - Patch
References () https://github.com/evmos/evmos/security/advisories/GHSA-pxv8-qhrh-jc7v - () https://github.com/evmos/evmos/security/advisories/GHSA-pxv8-qhrh-jc7v - Vendor Advisory
CVSS v2 : unknown
v3 : 3.5
v2 : unknown
v3 : 4.3
CPE cpe:2.3:a:evmos:evmos:*:*:*:*:*:*:*:*

07 Jun 2024, 14:56

Type Values Removed Values Added
Summary
  • (es) Evmos es el centro de máquinas virtuales Ethereum (EVM) en Cosmos Network. El saldo gastable no se actualiza correctamente al delegar tokens adquiridos. El problema permite que una cuenta de recuperación de derechos anticipe la liberación de tokens no adquiridos. Esta vulnerabilidad se solucionó en 18.0.0.

06 Jun 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-06 19:15

Updated : 2024-10-15 19:22


NVD link : CVE-2024-32873

Mitre link : CVE-2024-32873

CVE.ORG link : CVE-2024-32873


JSON object : View

Products Affected

evmos

  • evmos
CWE
CWE-682

Incorrect Calculation