Openzeppelin
Openzeppelin Contracts Upgradeable: vulnerabilidades y CVE
Openzeppelin Contracts Upgradeable tiene 12 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-27094 | Alta (7.4) | 0.76% | — | 21 mar 2024 | OpenZeppelin Contracts is a library for secure smart contract development. The `Base64.encode` function encodes a `bytes` input by iterating over it in chunks of 3 bytes. When this input is not a multiple of 3, the last… |
| CVE-2023-49798 | Alta (7.5) | 0.54% | — | 9 dic 2023 | OpenZeppelin Contracts is a library for smart contract development. A merge issue when porting the 5.0.1 patch to the 4.9 branch caused a line duplication. In the version of `Multicall.sol` released in… |
| CVE-2023-34459 | Media (5.9) | 0.37% | — | 16 jun 2023 | OpenZeppelin Contracts is a library for smart contract development. Starting in version 4.7.0 and prior to version 4.9.2, when the `verifyMultiProof`, `verifyMultiProofCalldata`, `procesprocessMultiProof`, or… |
| CVE-2023-34234 | Media (5.3) | 0.60% | — | 7 jun 2023 | OpenZeppelin Contracts is a library for smart contract development. By frontrunning the creation of a proposal, an attacker can become the proposer and gain the ability to cancel it. The attacker can do this repeatedly… |
| CVE-2023-30541 | Media (5.3) | 0.81% | — | 17 abr 2023 | OpenZeppelin Contracts is a library for secure smart contract development. A function in the implementation contract may be inaccessible if its selector clashes with one of the proxy's own selectors. Specifically, if… |
| CVE-2023-30542 | Alta (8.8) | 0.58% | — | 16 abr 2023 | OpenZeppelin Contracts is a library for secure smart contract development. The proposal creation entrypoint (`propose`) in `GovernorCompatibilityBravo` allows the creation of proposals with a `signatures` array shorter… |
| CVE-2023-26488 | Media (6.5) | 0.71% | — | 3 mar 2023 | OpenZeppelin Contracts is a library for secure smart contract development. The ERC721Consecutive contract designed for minting NFTs in batches does not update balances when a batch has size 1 and consists of a single… |
| CVE-2022-39384 | Media (5.6) | 0.53% | — | 4 nov 2022 | OpenZeppelin Contracts is a library for secure smart contract development. Before version 4.4.1 but after 3.2.0, initializer functions that are invoked separate from contract creation (the most prominent example being… |
| CVE-2022-35961 | Media (6.5) | 0.42% | — | 15 ago 2022 | OpenZeppelin Contracts is a library for secure smart contract development. The functions `ECDSA.recover` and `ECDSA.tryRecover` are vulnerable to a kind of signature malleability due to accepting EIP-2098 compact… |
| CVE-2022-35916 | Media (5.3) | 0.58% | — | 1 ago 2022 | OpenZeppelin Contracts is a library for secure smart contract development. Contracts using the cross chain utilities for Arbitrum L2, `CrossChainEnabledArbitrumL2` or `LibArbitrumL2`, will classify direct interactions… |
| CVE-2022-35915 | Media (5.3) | 0.78% | — | 1 ago 2022 | OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsInterface` query can cause unbounded gas consumption by returning a lot of data, while it is… |
| CVE-2022-31198 | Alta (7.5) | 0.77% | — | 1 ago 2022 | OpenZeppelin Contracts is a library for secure smart contract development. This issue concerns instances of Governor that use the module `GovernorVotesQuorumFraction`, a mechanism that determines quorum requirements as… |