Bifrost 中的 和 模块存在通道佣金归属方面的授权不当漏洞。签名账户在铸造代币时,可以传入任意已注册的 ,而系统未验证调用者是否有权限代表该通道进行代币铸造。这使得攻击者能够虚增某一通道的记录铸造量,从而在佣金结算时导致协议佣金被不成比例地分配给该通道。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Bitfrost.io | Bifrost | ≤ 2022.02 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Bitfrost.io | Bifrost | 0 ~ 2022.02 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet