PT-2022-23149 · Elrond · Elrond-Go
Iulianpascalau
·
Published
2022-09-01
·
Updated
2024-08-21
·
CVE-2022-36058
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
elrond-go versions prior to 1.3.34
Description
The issue affects elrond-go, the go implementation for the Elrond Network protocol. In affected versions, processing blocks that contain a
MultiESDTNFTTransfer transaction with a missing function name could cause problems. Basic functionality like p2p messaging, storage, and API requests are unaffected.Recommendations
For versions prior to 1.3.34, update to version 1.3.34 or higher to resolve the issue.
As a temporary workaround, consider avoiding the processing of blocks that contain
MultiESDTNFTTransfer transactions with missing function names until a patch is applied.
No other workarounds are available.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elrond-Go