Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qf7j-25g9-r63f

Опубликовано: 01 сент. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

elrond-go MultiESDTNFTTransfer call on a SC address with missing function name

Impact

Anyone who uses elrond-go to process blocks (historical or actual) that contains a transaction like this: MultiESDTNFTTransfer@01@54444558544b4b5955532d323631626138@00@0793afc18c8da2ca@ (mind the missing function name after the last @) Basic functionality like p2p messaging, storage, API requests and such are unaffected.

Patches

Patch v1.3.34 or higher

Workarounds

No workarounds

References

For future reference, one can observe the following integration test: [provide the link to the integration test]

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

github.com/ElrondNetwork/elrond-go

go
Затронутые версииВерсия исправления

<= 1.3.33

1.3.34

EPSS

Процентиль: 51%
0.00282
Низкий

7.5 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

Elrond go is the go implementation for the Elrond Network protocol. In versions prior to 1.3.34, anyone who uses elrond-go to process blocks (historical or actual) could encounter a `MultiESDTNFTTransfer` transaction like this: `MultiESDTNFTTransfer` with a missing function name. Basic functionality like p2p messaging, storage, API requests and such are unaffected. Version 1.3.34 contains a fix for this issue. There are no known workarounds.

EPSS

Процентиль: 51%
0.00282
Низкий

7.5 High

CVSS3

Дефекты

CWE-20