#VU49213 Improper access control in Loopring - CVE-2020-35962

 

#VU49213 Improper access control in Loopring - CVE-2020-35962

Published: January 3, 2021 / Updated: January 3, 2021


Vulnerability identifier: #VU49213
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:A/U:Amber
CVE-ID: CVE-2020-35962
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild
Vulnerable software:
Loopring
Software vendor:
Loopring Project

Description

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. The sellTokenForLRC function in the vault protocol in the smart contract implementation for Loopring (LRC), an Ethereum token, lacks access control for fee swapping and thus allows price manipulation.

Note, the vulnerability has been exploited in the wild in November 2020.


Remediation

Install updates from vendor's website.

External links