CVE-2024-32873

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. The spendable balance is not updated properly when delegating vested tokens. The issue allows a clawback vesting account to anticipate the release of unvested tokens. This vulnerability is fixed in 18.0.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:evmos:evmos:*:*:*:*:*:*:*:*

History

21 Nov 2024, 09:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : 3.5
References () https://github.com/evmos/evmos/commit/b2a09ca66613d8b04decd3f2dcba8e1e77709dcb - Patch () https://github.com/evmos/evmos/commit/b2a09ca66613d8b04decd3f2dcba8e1e77709dcb - Patch
References () https://github.com/evmos/evmos/security/advisories/GHSA-pxv8-qhrh-jc7v - Vendor Advisory () https://github.com/evmos/evmos/security/advisories/GHSA-pxv8-qhrh-jc7v - Vendor Advisory

15 Oct 2024, 19:22

Type Values Removed Values Added
References () https://github.com/evmos/evmos/commit/b2a09ca66613d8b04decd3f2dcba8e1e77709dcb - () https://github.com/evmos/evmos/commit/b2a09ca66613d8b04decd3f2dcba8e1e77709dcb - Patch
References () https://github.com/evmos/evmos/security/advisories/GHSA-pxv8-qhrh-jc7v - () https://github.com/evmos/evmos/security/advisories/GHSA-pxv8-qhrh-jc7v - Vendor Advisory
CPE cpe:2.3:a:evmos:evmos:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 3.5
v2 : unknown
v3 : 4.3
First Time Evmos
Evmos evmos

07 Jun 2024, 14:56

Type Values Removed Values Added
Summary
  • (es) Evmos es el centro de máquinas virtuales Ethereum (EVM) en Cosmos Network. El saldo gastable no se actualiza correctamente al delegar tokens adquiridos. El problema permite que una cuenta de recuperación de derechos anticipe la liberación de tokens no adquiridos. Esta vulnerabilidad se solucionó en 18.0.0.

06 Jun 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-06 19:15

Updated : 2024-11-21 09:15


NVD link : CVE-2024-32873

Mitre link : CVE-2024-32873

CVE.ORG link : CVE-2024-32873


JSON object : View

Products Affected

evmos

  • evmos
CWE
CWE-682

Incorrect Calculation