cbcvebase.
CVE-2022-35915
published 2022-08-01

CVE-2022-35915: OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsInterface` query can cause unbounded gas…

PriorityP425medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.66%
47.3th percentile
OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsInterface` query can cause unbounded gas consumption by returning a lot of data, while it is generally assumed that this operation has a bounded cost. The issue has been fixed in v4.7.2. Users are advised to upgrade. There are no known workarounds for this issue.

Affected

9 ranges
VendorProductVersion rangeFixed in
openzeppelincontracts>= 2.0.0 < 4.7.24.7.2
openzeppelincontracts>= 2.0.0 < 4.7.24.7.2
openzeppelincontracts-upgradeable>= 3.2.0 < 4.7.24.7.2
openzeppelincontracts_upgradeable>= 3.2.0 < 4.7.24.7.2
openzeppelinopenzeppelin-contracts
openzeppelinopenzeppelin-eth2.0.0 – 2.2.0
openzeppelinopenzeppelin-eth>= 2.0.0
openzeppelinopenzeppelin-solidity2.0.0 – 4.6.0
openzeppelinopenzeppelin-solidity>= 2.0.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.