VulnerabilityModified
CVE-2024-32873
The issue allows a clawback vesting account to anticipate the release of unvested tokens.
MEDIUM 4.3EPSS 0.38%
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. The spendable balance is not updated properly when delegating vested tokens. The issue allows a clawback vesting account to anticipate the release of unvested tokens. This vulnerability is fixed in 18.0.0.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.38% probability · 32th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-682
- Affected
- evmos/evmos
- Source
- security-advisories@github.com
References
- https://github.com/evmos/evmos/commit/b2a09ca66613d8b04decd3f2dcba8e1e77709dcbPatch
- https://github.com/evmos/evmos/security/advisories/GHSA-pxv8-qhrh-jc7vVendor Advisory
- https://github.com/evmos/evmos/commit/b2a09ca66613d8b04decd3f2dcba8e1e77709dcbPatch
- https://github.com/evmos/evmos/security/advisories/GHSA-pxv8-qhrh-jc7vVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.