ZeroHour

CVE-2024-27094

CVSS 3.1
7.4 high
EPSS
<1%p53
Published
()
Modified
Description

OpenZeppelin Contracts is a library for secure smart contract development. The `Base64.encode` function encodes a `bytes` input by iterating over it in chunks of 3 bytes. When this input is not a multiple of 3, the last iteration may read parts of the memory that are beyond the input buffer. The vulnerability is fixed in 5.0.2 and 4.9.6.

Vendors
openzeppelin
Products
contracts, contracts upgradeable
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.