NA

CVE-2022-35915

Published: 01/08/2022 Updated: 21/07/2023
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsInterface` query can cause unbounded gas consumption by returning a lot of data, while it is generally assumed that this operation has a bounded cost. The issue has been fixed in v4.7.2. Users are advised to upgrade. There are no known workarounds for this issue.

Vulnerable Product Search on Vulmon Subscribe to Product

openzeppelin openzeppelin-solidity

openzeppelin contracts

openzeppelin openzeppelin-eth

openzeppelin contracts upgradeable