GHSA-4h98-2769-gh6h

    Dashboard / Vulnerabilities / GHSA-4h98-2769-gh6h

    GHSA-4h98-2769-gh6h

    Published: 18 Aug 2022Last Modified: 8 Nov 2023

    Summary: OpenZeppelin Contracts vulnerable to ECDSA signature malleability

    Details: ### Impact The functions `ECDSA.recover` and `ECDSA.tryRecover` are vulnerable to a kind of signature malleability due to accepting EIP-2098 compact signatures in addition to the traditional 65 byte signature format. This is only an issue for the functions that take a single `bytes` argument, and not the functions that take `r, v, s` or `r, vs` as separate arguments. The potentially affected contracts are those that implement signature reuse or replay protection by marking the signature itself as used rather than the signed message or a nonce included in it. A user may take a signature that has already been submitted, submit it again in a different form, and bypass this protection. ### Patches The issue has been patched in 4.7.3. ### For more information If you have any questions or comments about this advisory, or need assistance deploying a fix, email us at [[email protected]](mailto:[email protected]).

    Affected packages

    Package

    Name: @openzeppelin/contracts

    Purl: pkg:npm/%40openzeppelin/contracts

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 4.1.0
    Fixed -4.7.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-4h98-2769-gh6h | CVE-DB