GHSA-q4h9-46xg-m3x9

    Dashboard / Vulnerabilities / GHSA-q4h9-46xg-m3x9

    GHSA-q4h9-46xg-m3x9

    Published: 15 Sept 2021Last Modified: 14 Sept 2021

    Summary: UUPSUpgradeable vulnerability in @openzeppelin/contracts-upgradeable

    Details: ### Impact Upgradeable contracts using `UUPSUpgradeable` may be vulnerable to an attack affecting uninitialized implementation contracts. We will update this advisory with more information soon. ### Patches A fix is included in version 4.3.2 of `@openzeppelin/contracts` and `@openzeppelin/contracts-upgradeable`. ### Workarounds Initialize implementation contracts using `UUPSUpgradeable` by invoking the initializer function (usually called `initialize`). An example is provided [in the forum](https://forum.openzeppelin.com/t/security-advisory-initialize-uups-implementation-contracts/15301). ### References A post-mortem will be published in a few days in the [OpenZeppelin Forum](https://forum.openzeppelin.com/). ### For more information If you have any questions or comments about this advisory, or need assistance executing the mitigation, email us at [email protected].

    Affected packages

    Package

    Name: @openzeppelin/contracts-upgradeable

    Purl: pkg:npm/%40openzeppelin/contracts-upgradeable

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 4.1.0
    Fixed -4.3.2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-q4h9-46xg-m3x9 | CVE-DB