漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
TimelockController vulnerability in OpenZeppelin Contracts
Vulnerability Description
OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executor role to escalate privileges. Further details about the vulnerability will be disclosed at a later date. As a workaround revoke the executor role from accounts not strictly under the team's control. We recommend revoking all executors that are not also proposers. When applying this mitigation, ensure there is at least one proposer and executor remaining.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
特权管理不恰当
Vulnerability Title
OpenZepplin 安全漏洞
Vulnerability Description
OpenZepplin是一个用于智能合约开发的库。 OpenZepplin 存在安全漏洞,该漏洞允许具有执行者角色的参与者提升权限。
CVSS Information
N/A
Vulnerability Type
N/A