PT-2022-23149 · Elrond · Elrond-Go

Iulianpascalau

·

Published

2022-09-01

·

Updated

2024-08-21

·

CVE-2022-36058

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions elrond-go versions prior to 1.3.34
Description The issue affects elrond-go, the go implementation for the Elrond Network protocol. In affected versions, processing blocks that contain a MultiESDTNFTTransfer transaction with a missing function name could cause problems. Basic functionality like p2p messaging, storage, and API requests are unaffected.
Recommendations For versions prior to 1.3.34, update to version 1.3.34 or higher to resolve the issue. As a temporary workaround, consider avoiding the processing of blocks that contain MultiESDTNFTTransfer transactions with missing function names until a patch is applied. No other workarounds are available.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-36058
GHSA-QF7J-25G9-R63F
GO-2022-0970

Affected Products

Elrond-Go