5
CVSSv2

CVE-2019-20809

Published: 03/06/2020 Updated: 21/07/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The price oracle in PriceOracle.sol in Compound Finance Compound Price Oracle 1.0 up to and including 2.0 allows a price poster to set an invalid asset price via the setPrice function, and consequently violate the intended limits on price swings.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

compound price oracle