CVE-2019-16214
Libra Core antes del 03-09-2019, presenta una expresión regular errónea para comentarios en línea, lo que hace más fácil para que atacantes interfieran con la auditoria del código mediante el uso de un carácter de salto de línea no estándar para un comentario. Por ejemplo, un autor del módulo Move puede ingresar la secuencia // (que introduce un comentario de una sola línea), seguido por un texto de comentario muy breve, el carácter \r y el código que posee una funcionalidad crítica para la seguridad.
Leer descripción completaMostrar menos
En muchos entornos populares, este código es desplegado en una línea separada y, por lo tanto, un lector puede inferir que el código está ejecutado. Sin embargo, el código NO se ejecuta, porque el archivo language/compiler/ir_to_bytecode/src/parser.rs permite que el comentario continúe después del carácter \r.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
- Puntuación base: 5.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.32%
- Percentil entre todas las CVEs puntuadas: 70
- Fecha de la puntuación: 10/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
- https://blog.openzeppelin.com/libra-vulnerability-release/
- https://blog.openzeppelin.com/libra-vulnerability-summary/
- https://github.com/libra/libra/commit/7efb0221989f17fdf7f8486730898ed947a1e19e
- https://blog.openzeppelin.com/libra-vulnerability-release/
- https://blog.openzeppelin.com/libra-vulnerability-summary/
- https://github.com/libra/libra/commit/7efb0221989f17fdf7f8486730898ed947a1e19e
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-16214",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.7,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.1
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2019-09-11T04:15:11.887",
"references": [
{
"url": "https://blog.openzeppelin.com/libra-vulnerability-release/",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://blog.openzeppelin.com/libra-vulnerability-summary/",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/libra/libra/commit/7efb0221989f17fdf7f8486730898ed947a1e19e",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://blog.openzeppelin.com/libra-vulnerability-release/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://blog.openzeppelin.com/libra-vulnerability-summary/",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/libra/libra/commit/7efb0221989f17fdf7f8486730898ed947a1e19e",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Libra Core before 2019-09-03 has an erroneous regular expression for inline comments, which makes it easier for attackers to interfere with code auditing by using a nonstandard line-break character for a comment. For example, a Move module author can enter the // sequence (which introduces a single-line comment), followed by very brief comment text, the \\r character, and code that has security-critical functionality. In many popular environments, this code is displayed on a separate line, and thus a reader may infer that the code is executed. However, the code is NOT executed, because language/compiler/ir_to_bytecode/src/parser.rs allows the comment to continue after the \\r character."
},
{
"lang": "es",
"value": "Libra Core antes del 03-09-2019, presenta una expresión regular errónea para comentarios en línea, lo que hace más fácil para que atacantes interfieran con la auditoria del código mediante el uso de un carácter de salto de línea no estándar para un comentario. Por ejemplo, un autor del módulo Move puede ingresar la secuencia // (que introduce un comentario de una sola línea), seguido por un texto de comentario muy breve, el carácter \\r y el código que posee una funcionalidad crítica para la seguridad. En muchos entornos populares, este código es desplegado en una línea separada y, por lo tanto, un lector puede inferir que el código está ejecutado. Sin embargo, el código NO se ejecuta, porque el archivo language/compiler/ir_to_bytecode/src/parser.rs permite que el comentario continúe después del carácter \\r."
}
],
"lastModified": "2026-06-17T02:21:54.570",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:libra:libra_core:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A2E55F3B-1682-470D-83BA-9452A91FBF98",
"versionEndExcluding": "2019-09-03"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}