CVE-2022-36061
Dashboard / Vulnerabilities / CVE-2022-36061
CVE-2022-36061
Summary: Elrond go can execute on same context checks in VM
Details: Elrond go is the go implementation for the Elrond Network protocol. In versions prior to 1.3.35, read only calls between contracts can generate smart contracts results. For example, if contract A calls in read only mode contract B and the called function will make changes upon the contract's B state, the state will be altered for contract B as if the call was not made in the read-only mode. This can lead to some effects not designed by the original smart contracts programmers. This issue was patched in version 1.3.35. There are no known workarounds.
References: https://github.com/ElrondNetwork/elrond-go/blob/8e402fa6d7e91e779980122d3798b2bf50892945/integrationTests/vm/txsFee/asyncESDT_test.go#L452, https://github.com/ElrondNetwork/elrond-go/releases/tag/v1.3.35, https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/36xxx/CVE-2022-36061.json, https://github.com/ElrondNetwork/elrond-go/security/advisories/GHSA-mv8x-668m-53fg, https://nvd.nist.gov/vuln/detail/CVE-2022-36061
Affected packages
Package
Name:
Purl:
