CVE-2022-35916

Source
https://cve.org/CVERecord?id=CVE-2022-35916
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-35916.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-35916
Aliases
Published
2022-08-01T21:00:30Z
Modified
2026-04-10T04:49:09.641353Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Cross chain utilities for Arbitrum L2 see EOA calls as cross chain calls
Details

OpenZeppelin Contracts is a library for secure smart contract development. Contracts using the cross chain utilities for Arbitrum L2, CrossChainEnabledArbitrumL2 or LibArbitrumL2, will classify direct interactions of externally owned accounts (EOAs) as cross chain calls, even though they are not started on L1. This issue has been patched in v4.7.2. Users are advised to upgrade. There are no known workarounds for this issue.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/35xxx/CVE-2022-35916.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-669"
    ]
}
References

Affected packages

Git / github.com/openzeppelin/openzeppelin-contracts

Affected ranges

Type
GIT
Repo
https://github.com/openzeppelin/openzeppelin-contracts
Events

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-35916.json"