cbcvebase.
CVE-2024-27094
published 2024-03-21

CVE-2024-27094: OpenZeppelin Contracts is a library for secure smart contract development. The `Base64.encode` function encodes a `bytes` input by iterating over it in chunks…

PriorityP340high7.4CVSS 3.1
AVNACHPRNUINSUCHINAH
EPSS
0.76%
51.2th percentile
OpenZeppelin Contracts is a library for secure smart contract development. The `Base64.encode` function encodes a `bytes` input by iterating over it in chunks of 3 bytes. When this input is not a multiple of 3, the last iteration may read parts of the memory that are beyond the input buffer. The vulnerability is fixed in 5.0.2 and 4.9.6.

Affected

10 ranges
VendorProductVersion rangeFixed in
openzeppelincontracts>= 4.5.0 < 4.9.64.9.6
openzeppelincontracts>= 4.5.0 < 4.9.64.9.6
openzeppelincontracts>= 5.0.0 < 5.0.25.0.2
openzeppelincontracts>= 5.0.0-rc.0 < 5.0.25.0.2
openzeppelincontracts-upgradeable>= 4.5.0 < 4.9.64.9.6
openzeppelincontracts-upgradeable>= 5.0.0-rc.0 < 5.0.25.0.2
openzeppelincontracts_upgradeable4.5.0 – 4.9.6
openzeppelincontracts_upgradeable>= 5.0.0 < 5.0.25.0.2
openzeppelinopenzeppelin-contracts
openzeppelinopenzeppelin-contracts
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.