Description
Versions of bigint-money prior to 0.6.2 are vulnerable to an Incorrect Calculation. The package incorrectly rounded certain numbers, which could have drastic consequences due to its usage in financial systems.
Recommendation
Update the bigint-money package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.6.2
- Patched version(s): 0.6.2
References
Could your website be exposed too?
SmartScanner can check your website for Incorrect Calculation in bigint-money and gives you actionable findings to investigate.
Start a free scanRelated Issues
- CKEditor4 Cross-site Scripting vulnerability caused by incorrect CDATA detection - CVE-2024-24815
- Incorrect default cookie name and recommendation - Vulnerability
- Incorrect Account Used for Signing - eth-ledger-bridge-keyring - Vulnerability
- Incorrect Account Used for Signing - Vulnerability


