GHSA-wmpv-c2jp-j2xg

    Dashboard / Vulnerabilities / GHSA-wmpv-c2jp-j2xg

    GHSA-wmpv-c2jp-j2xg

    Published: 15 Nov 2021Last Modified: 15 Nov 2021

    Summary: ERC1155Supply vulnerability in OpenZeppelin Contracts

    Details: When ERC1155 tokens are minted, a callback is invoked on the receiver of those tokens, as required by the spec. When including the `ERC1155Supply` extension, total supply is not updated until after the callback, thus during the callback the reported total supply is lower than the real number of tokens in circulation. ### Impact If a system relies on accurately reported supply, an attacker may be able to mint tokens and invoke that system after receiving the token balance but before the supply is updated. ### Patches A fix is included in version 4.3.3 of `@openzeppelin/contracts` and `@openzeppelin/contracts-upgradeable`. ### Workarounds If accurate supply is relevant, do not mint tokens to untrusted receivers. ### Credits The issue was identified and reported by @ChainSecurityAudits. ### For more information Read [TotalSupply Inconsistency in ERC1155 NFT Tokens](https://medium.com/chainsecurity/totalsupply-inconsistency-in-erc1155-nft-tokens-8f8e3b29f5aa) by @ChainSecurityAudits for a more detailed breakdown. If you have any questions or comments about this advisory, email us at [email protected].

    Affected packages

    Package

    Name: @openzeppelin/contracts

    Purl: pkg:npm/%40openzeppelin/contracts

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 4.2.0
    Fixed -4.3.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-wmpv-c2jp-j2xg | CVE-DB