Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
TimelockController vulnerability in OpenZeppelin Contracts
Vulnerability Description
OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executor role to escalate privileges. Further details about the vulnerability will be disclosed at a later date. As a workaround revoke the executor role from accounts not strictly under the team's control. We recommend revoking all executors that are not also proposers. When applying this mitigation, ensure there is at least one proposer and executor remaining.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
特权管理不恰当
Vulnerability Title
OpenZepplin 安全漏洞
Vulnerability Description
OpenZepplin是一个用于智能合约开发的库。 OpenZepplin 存在安全漏洞,该漏洞允许具有执行者角色的参与者提升权限。
CVSS Information
N/A
Vulnerability Type
N/A