PT-2022-23150 · Elrond · Elrond-Go

Iulianpascalau

·

Published

2022-09-06

·

Updated

2024-08-21

·

CVE-2022-36061

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Elrond go versions prior to 1.3.35
Description The issue concerns read-only calls between contracts in the Elrond Network protocol, which can generate smart contract results and alter the state of the called contract as if the call was not made in read-only mode. This can lead to unintended effects not designed by the original smart contract programmers.
Recommendations For versions prior to 1.3.35, update to version 1.3.35 or higher to resolve the issue. At the moment, there are no known workarounds for this issue.

Exploit

Fix

Improper Initialization

Weakness Enumeration

Related Identifiers

CVE-2022-36061
GHSA-MV8X-668M-53FG
GO-2022-0971

Affected Products

Elrond-Go