Description
Versions of bigint-money prior to 0.6.2 are vulnerable to an Incorrect Calculation. The package incorrectly rounded certain numbers, which could have drastic consequences due to its usage in financial systems.
Recommendation
Update the bigint-money package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.6.2
- Patched version(s): 0.6.2
References
Related Issues
- CKEditor4 Cross-site Scripting vulnerability caused by incorrect CDATA detection - CVE-2024-24815
- Incorrect default cookie name and recommendation - Vulnerability
- Incorrect Account Used for Signing - eth-ledger-bridge-keyring - Vulnerability
- Incorrect Account Used for Signing - Vulnerability
You might also like:
- Tags:
- npm
- bigint-money
Anything's wrong? Let us know Last updated on January 09, 2023


