Логотип exploitDog
bind:CVE-2023-49798
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-49798

Количество 2

Количество 2

nvd логотип

CVE-2023-49798

около 2 лет назад

OpenZeppelin Contracts is a library for smart contract development. A merge issue when porting the 5.0.1 patch to the 4.9 branch caused a line duplication. In the version of `Multicall.sol` released in `@openzeppelin/contracts@4.9.4` and `@openzeppelin/contracts-upgradeable@4.9.4`, all subcalls are executed twice. Concretely, this exposes a user to unintentionally duplicate operations like asset transfers. The duplicated delegatecall was removed in version 4.9.5. The 4.9.4 version is marked as deprecated. Users are advised to upgrade. There are no known workarounds for this issue.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-699g-q6qh-q4v8

около 2 лет назад

OpenZeppelin Contracts and Contracts Upgradeable duplicated execution of subcalls in v4.9.4

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-49798

OpenZeppelin Contracts is a library for smart contract development. A merge issue when porting the 5.0.1 patch to the 4.9 branch caused a line duplication. In the version of `Multicall.sol` released in `@openzeppelin/contracts@4.9.4` and `@openzeppelin/contracts-upgradeable@4.9.4`, all subcalls are executed twice. Concretely, this exposes a user to unintentionally duplicate operations like asset transfers. The duplicated delegatecall was removed in version 4.9.5. The 4.9.4 version is marked as deprecated. Users are advised to upgrade. There are no known workarounds for this issue.

CVSS3: 5.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-699g-q6qh-q4v8

OpenZeppelin Contracts and Contracts Upgradeable duplicated execution of subcalls in v4.9.4

CVSS3: 5.9
0%
Низкий
около 2 лет назад

Уязвимостей на страницу