CVE-2021-39167
Published: Aug 26, 2021
Modified: Aug 4, 2024
CVSS v3.1
10.0
Description
OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executor role to escalate privileges. Further details about the vulnerability will be disclosed at a later date. As a workaround revoke the executor role from accounts not strictly under the team's control. We recommend revoking all executors that are not also proposers. When applying this mitigation, ensure there is at least one proposer and executor remaining.
| Vendor | Product | Versions |
|---|---|---|
OpenZeppelin | openzeppelin-contracts | affected >=4.0.0, < 4.3.1affected >=3.3.0, < 3.4.2affected >= 3.3.0-solc-0.7, < 3.4.2-solc-0.7 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now