Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-34704

Опубликовано: 14 мая 2024
Источник: nvd
CVSS3: 5.9
EPSS Низкий

Описание

era-compiler-solidity is the ZKsync compiler for Solidity. The problem occurred during instruction selection in the DAGCombine phase while visiting the XOR operation. The issue arises when attempting to fold the expression !(x cc y) into (x !cc y). To perform this transformation, the second operand of XOR should be a constant representing the true value. However, it was incorrectly assumed that -1 represents the true value, when in fact, 1 is the correct representation, so this transformation for this case should be skipped. This vulnerability is fixed in 1.4.1.

EPSS

Процентиль: 53%
0.00304
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-682

EPSS

Процентиль: 53%
0.00304
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-682