Back to overview

CVE-2021-39167

CRITICAL
10.0
CVSS 3.1
Description
OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executor role to escalate privileges. Further details about the vulnerability will be disclosed at a later date. As a workaround revoke the executor role from accounts not strictly under the team's control. We recommend revoking all executors that are not also proposers. When applying this mitigation, ensure there is at least one proposer and executor remaining.

Metadata

CVE ID
CVE-2021-39167
State
PUBLISHED
Assigner
GitHub_M
Reserved
2021-08-16 00:00 UTC
Published
2021-08-26 23:35 UTC
Last updated
2024-08-04 01:58 UTC
Primary CWE
CWE-269
CWE-269: Improper Privilege Management
Vendor / Product
OpenZeppelin / openzeppelin-contracts
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
OpenZeppelin openzeppelin-contracts >=4.0.0, < 4.3.1, >=3.3.0, < 3.4.2, >= 3.3.0-solc-0.7, < 3.4.2-solc-0.7
Weakness (CWE)
CWESourceDescription
CWE-269 cna CWE-269: Improper Privilege Management
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview