CVE-2018-12056
15.08.2018, 17:29
The maxRandom function of a smart contract implementation for All For One, an Ethereum gambling game, generates a random value with publicly readable variables because the _seed value can be retrieved with a getStorageAt call. Therefore, it allows attackers to always win and get rewards.
Vendor | Product | Version |
---|---|---|
all-for-one | all_for_one | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References