SCA: security update for github.com/evmos/evmos/v10, github.com/evmos/evmos/v11, github.com/evmos/evmos/v12, github.com/evmos/evmos/v13, github.com/evmos/evmos/v14, github.com/evmos/evmos/v15, github.com/evmos/evmos/v16, github.com/evmos/evmos/v17, github.com/evmos/evmos/v18, github.com/evmos/evmos/v6, github.com/evmos/evmos/v7, github.com/evmos/evmos/v8, github.com/evmos/evmos/v9 (GHSA-xgr7-jgq3-mhmc)

high Tenable Cloud Security Plugin ID 420500

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. There is an issue with how to
liquid stake using Safe which itself is a contract. The bug only appears when there is a local state
change together with an ICS20 transfer in the same function and uses the contract's balance, that is using
the contract address as the sender parameter in an ICS20 transfer using the ICS20 precompile. This is in
essence the "infinite money glitch" allowing contracts to double the supply of Evmos after each
transaction.The issue has been patched in versions >=V18.1.0. (CVE-2024-37153)

See Also

https://github.com/advisories/GHSA-xgr7-jgq3-mhmc

Plugin Details

Severity: High

ID: 420500

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.51

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

CVSS Score Source: CVE-2024-37153

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/6/2024

Vulnerability Publication Date: 6/6/2024

Reference Information

CVE: CVE-2024-37153

cwe: CWE-670