The _deposit function in the smart contract implementation for Stable Yield Credit (yCREDIT), an Ethereum token, has certain incorrect calculations. An attacker can obtain more yCREDIT tokens than they should.
References
Link | Resource |
---|---|
https://blocksecteam.medium.com/deposit-less-get-more-ycredit-attack-details-f589f71674c3 | Exploit Third Party Advisory |
https://etherscan.io/address/0xe0839f9b9688a77924208ad509e29952dc660261 | Third Party Advisory |
Configurations
Information
Published : 2021-01-02 20:15
Updated : 2021-01-07 12:52
NVD link : CVE-2021-3004
Mitre link : CVE-2021-3004
JSON object : View
CWE
CWE-682
Incorrect Calculation
Products Affected
stableyieldcredit_project
- stableyieldcredit