Логотип exploitDog
bind:CVE-2021-41264
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-41264

Количество 2

Количество 2

nvd логотип

CVE-2021-41264

около 4 лет назад

OpenZeppelin Contracts is a library for smart contract development. In affected versions upgradeable contracts using `UUPSUpgradeable` may be vulnerable to an attack affecting uninitialized implementation contracts. A fix is included in version 4.3.2 of `@openzeppelin/contracts` and `@openzeppelin/contracts-upgradeable`. For users unable to upgrade; initialize implementation contracts using `UUPSUpgradeable` by invoking the initializer function (usually called `initialize`). An example is provided [in the forum](https://forum.openzeppelin.com/t/security-advisory-initialize-uups-implementation-contracts/15301).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-5vp3-v4hc-gx76

больше 4 лет назад

UUPSUpgradeable vulnerability in @openzeppelin/contracts

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-41264

OpenZeppelin Contracts is a library for smart contract development. In affected versions upgradeable contracts using `UUPSUpgradeable` may be vulnerable to an attack affecting uninitialized implementation contracts. A fix is included in version 4.3.2 of `@openzeppelin/contracts` and `@openzeppelin/contracts-upgradeable`. For users unable to upgrade; initialize implementation contracts using `UUPSUpgradeable` by invoking the initializer function (usually called `initialize`). An example is provided [in the forum](https://forum.openzeppelin.com/t/security-advisory-initialize-uups-implementation-contracts/15301).

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-5vp3-v4hc-gx76

UUPSUpgradeable vulnerability in @openzeppelin/contracts

CVSS3: 9.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу