OSV 1.4.0 · github-reviewed · 修改于 2021-09-15 06:17
发布时间
2021-09-16 04:22
GitHub 审查时间
2021-09-15 06:17
NVD 发布时间
—
源文件
advisories/github-reviewed/2021/09/GHSA-q4h9-46xg-m3x9/GHSA-q4h9-46xg-m3x9.json
Upgradeable contracts using UUPSUpgradeable may be vulnerable to an attack affecting uninitialized implementation contracts. We will update this advisory with more information soon.
A fix is included in version 4.3.2 of @openzeppelin/contracts and @openzeppelin/contracts-upgradeable.
Initialize implementation contracts using UUPSUpgradeable by invoking the initializer function (usually called initialize). An example is provided in the forum.
A post-mortem will be published in a few days in the OpenZeppelin Forum.
If you have any questions or comments about this advisory, or need assistance executing the mitigation, email us at [email protected].