Vulnerability Description
The price oracle in PriceOracle.sol in Compound Finance Compound Price Oracle 1.0 through 2.0 allows a price poster to set an invalid asset price via the setPrice function, and consequently violate the intended limits on price swings.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Compound | Price Oracle | >= 1.0, <= 2.0 |
References
- https://privacylog.blogspot.com/2019/10/compound-finance-zero-day-prices-can.htmMitigationThird Party Advisory
- https://privacylog.blogspot.com/2019/10/compound-finance-zero-day-prices-can.htmMitigationThird Party Advisory
FAQ
What is CVE-2019-20809?
CVE-2019-20809 is a vulnerability with a CVSS score of 7.5 (HIGH). The price oracle in PriceOracle.sol in Compound Finance Compound Price Oracle 1.0 through 2.0 allows a price poster to set an invalid asset price via the setPrice function, and consequently violate th...
How severe is CVE-2019-20809?
CVE-2019-20809 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-20809?
Check the references section above for vendor advisories and patch information. Affected products include: Compound Price Oracle.