cbcvebase.

Openzeppelin Contracts vulnerabilities

23 known vulnerabilities affecting openzeppelin/contracts.

Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH7MEDIUM13

Vulnerabilities

Page 2 of 2
CVE-2022-35916P4MEDIUMCVSS 5.3≥ 4.6.0, < 4.7.22022-08-01
CVE-2022-35916 [MEDIUM] CWE-669 CVE-2022-35916: OpenZeppelin Contracts is a library for secure smart contract development. Contracts using the cross OpenZeppelin Contracts is a library for secure smart contract development. Contracts using the cross chain utilities for Arbitrum L2, `CrossChainEnabledArbitrumL2` or `LibArbitrumL2`, will classify direct interactions of externally owned accounts (EOAs) as cross chain calls, even though they are not started on L1. This issue has been patched in v4.7
ghsanvdosv
CVE-2023-30541P4MEDIUMCVSS 5.3≥ 3.2.0, < 4.8.32023-04-17
CVE-2023-30541 [MEDIUM] CWE-436 CVE-2023-30541: OpenZeppelin Contracts is a library for secure smart contract development. A function in the impleme OpenZeppelin Contracts is a library for secure smart contract development. A function in the implementation contract may be inaccessible if its selector clashes with one of the proxy's own selectors. Specifically, if the clashing function has a different signature with incompatible ABI encoding, the proxy could revert while attempting to decode the
ghsanvdosv
CVE-2023-40014P4MEDIUM≥ 4.0.0, < 4.9.32023-08-11
CVE-2023-40014 [MEDIUM] CWE-116 OpenZeppelin Contracts vulnerable to Improper Escaping of Output OpenZeppelin Contracts vulnerable to Improper Escaping of Output ### Impact OpenZeppelin Contracts is a library for secure smart contract development. Starting in version 4.0.0 and prior to version 4.9.3, contracts using `ERC2771Context` along with a custom trusted forwarder may see `_msgSender` return `address(0)` in calls that originate from the forwarder with calldata shorter than 20 bytes. This
ghsaosv
Openzeppelin Contracts vulnerabilities | cvebase