PT-2022-37397 · Openzeppelin · Openzeppelin Contracts For Cairo

Published

2022-07-15

·

Updated

2022-07-15

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenZeppelin Contracts for Cairo version 0.2.0
Description The issue affects account contracts, rendering them unusable on live networks. This problem impacts all accounts, including vanilla and ethereum flavors, in the v0.2.0 release that are not whitelisted on StarkNet mainnet. Only goerli deployments of v0.2.0 accounts are affected. The faulty behavior is not observed in StarkNet's testing framework.
Recommendations For version 0.2.0, update to version 0.2.1 to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2022-43143

Affected Products

Openzeppelin Contracts For Cairo