Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-35961

Опубликовано: 15 авг. 2022
Источник: nvd
CVSS3: 7.9
CVSS3: 6.5
EPSS Низкий

Описание

OpenZeppelin Contracts is a library for secure smart contract development. The functions ECDSA.recover and ECDSA.tryRecover are vulnerable to a kind of signature malleability due to accepting EIP-2098 compact signatures in addition to the traditional 65 byte signature format. This is only an issue for the functions that take a single bytes argument, and not the functions that take r, v, s or r, vs as separate arguments. The potentially affected contracts are those that implement signature reuse or replay protection by marking the signature itself as used rather than the signed message or a nonce included in it. A user may take a signature that has already been submitted, submit it again in a different form, and bypass this protection. The issue has been patched in 4.7.3.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openzeppelin:contracts:*:*:*:*:*:node.js:*:*
Версия от 4.1.0 (включая) до 4.7.3 (исключая)
cpe:2.3:a:openzeppelin:contracts_upgradeable:*:*:*:*:*:node.js:*:*
Версия от 4.1.0 (включая) до 4.7.3 (исключая)

EPSS

Процентиль: 37%
0.00156
Низкий

7.9 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-354

Связанные уязвимости

CVSS3: 7.9
github
больше 3 лет назад

OpenZeppelin Contracts vulnerable to ECDSA signature malleability

EPSS

Процентиль: 37%
0.00156
Низкий

7.9 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-354