CVE-2022-36061
Estado: ModificadaCrítica (9.8)—
Elrond go is the go implementation for the Elrond Network protocol. In versions prior to 1.3.35, read only calls between contracts can generate smart contracts results. For example, if contract A calls in read only mode contract B and the called function will make changes upon the contract's B state, the state will be altered for contract B as if the call was not made in the read-only mode. This can lead to some effects not designed by the original smart contracts programmers. This issue was patched in version 1.3.35. There are no known workarounds.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.25%
- Percentil entre todas las CVEs puntuadas: 68
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-665
Referencias
- https://github.com/ElrondNetwork/elrond-go/blob/8e402fa6d7e91e779980122d3798b2bf50892945/integrationTests/vm/txsFee/asyncESDT_test.go#L452
- https://github.com/ElrondNetwork/elrond-go/releases/tag/v1.3.35
- https://github.com/ElrondNetwork/elrond-go/security/advisories/GHSA-mv8x-668m-53fg
- https://github.com/ElrondNetwork/elrond-go/blob/8e402fa6d7e91e779980122d3798b2bf50892945/integrationTests/vm/txsFee/asyncESDT_test.go#L452
- https://github.com/ElrondNetwork/elrond-go/releases/tag/v1.3.35
- https://github.com/ElrondNetwork/elrond-go/security/advisories/GHSA-mv8x-668m-53fg
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-36061",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-36061",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-04-22T15:39:41.510137Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.5,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "ElrondNetwork",
"product": "elrond-go",
"versions": [
{
"status": "affected",
"version": "< 1.3.35"
}
]
}
]
}
],
"published": "2022-09-06T21:15:08.633",
"references": [
{
"url": "https://github.com/ElrondNetwork/elrond-go/blob/8e402fa6d7e91e779980122d3798b2bf50892945/integrationTests/vm/txsFee/asyncESDT_test.go#L452",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/ElrondNetwork/elrond-go/releases/tag/v1.3.35",
"tags": [
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/ElrondNetwork/elrond-go/security/advisories/GHSA-mv8x-668m-53fg",
"tags": [
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/ElrondNetwork/elrond-go/blob/8e402fa6d7e91e779980122d3798b2bf50892945/integrationTests/vm/txsFee/asyncESDT_test.go#L452",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/ElrondNetwork/elrond-go/releases/tag/v1.3.35",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/ElrondNetwork/elrond-go/security/advisories/GHSA-mv8x-668m-53fg",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-665"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Elrond go is the go implementation for the Elrond Network protocol. In versions prior to 1.3.35, read only calls between contracts can generate smart contracts results. For example, if contract A calls in read only mode contract B and the called function will make changes upon the contract's B state, the state will be altered for contract B as if the call was not made in the read-only mode. This can lead to some effects not designed by the original smart contracts programmers. This issue was patched in version 1.3.35. There are no known workarounds."
},
{
"lang": "es",
"value": "Elrond go es la implementación go para el protocolo de la Red Elrond. En versiones anteriores a la 1.3.35, las llamadas de sólo lectura entre contratos pueden generar resultados de contratos inteligentes. Por ejemplo, si el contrato A llama en modo de sólo lectura al contrato B y la función llamada realiza cambios sobre el estado del contrato B, el estado será alterado para el contrato B como si la llamada no fuera realizada en modo de sólo lectura. Esto puede conllevar a algunos efectos no diseñados por los programadores de los contratos inteligentes originales. Este problema fue parcheado en versión 1.3.35. No se presentan mitigaciones conocidas.\n"
}
],
"lastModified": "2026-06-17T04:52:50.113",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:elrond:elrond_go:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "56E3CD21-6971-4E78-86B7-769469400236",
"versionEndExcluding": "1.3.35"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}