CVE-2019-20809
03.06.2020, 17:15
The price oracle in PriceOracle.sol in Compound Finance Compound Price Oracle 1.0 through 2.0 allows a price poster to set an invalid asset price via the setPrice function, and consequently violate the intended limits on price swings.Enginsight
Vendor | Product | Version |
---|---|---|
compound | price_oracle | 1.0 ≤ 𝑥 ≤ 2.0 |
𝑥
= Vulnerable software versions