GHSA-7grf-83vw-6f5x
Dashboard / Vulnerabilities / GHSA-7grf-83vw-6f5x
Summary: OpenZeppelin Contracts ERC165Checker unbounded gas consumption
Details: ### Impact The target contract of an EIP-165 `supportsInterface` query can cause unbounded gas consumption by returning a lot of data, while it is generally assumed that this operation has a bounded cost. ### Patches The issue has been fixed in v4.7.2. ### References https://github.com/OpenZeppelin/openzeppelin-contracts/pull/3587 ### For more information If you have any questions or comments about this advisory, or need assistance deploying a fix, email us at [[email protected]](mailto:[email protected]).
References: https://github.com/OpenZeppelin/openzeppelin-contracts/security/advisories/GHSA-7grf-83vw-6f5x, https://nvd.nist.gov/vuln/detail/CVE-2022-35915, https://github.com/OpenZeppelin/openzeppelin-contracts/pull/3587, https://github.com/OpenZeppelin/openzeppelin-contracts, https://github.com/OpenZeppelin/openzeppelin-contracts/releases/tag/v4.7.2
Affected packages
Package
Name: @openzeppelin/contracts
Purl: pkg:npm/%40openzeppelin/contracts
Affected ranges
Type: SEMVER
Events:
