Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In OpenZeppelin <=v4.4.0, initializer functions that are invoked separate from contract creation (the most prominent example being minimal proxies) may be reentered if they make an untrusted non-view external call. Once an initializer has finished running it can never be re-executed. However, an exception put in place to support multiple inheritance made reentrancy possible, breaking the expectation that there is a single execution.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenZeppelin 安全漏洞
Vulnerability Description
OpenZeppelin是一个应用软件。一个安全区块链应用的标准。 OpenZeppelin <=v4.4.0中存在安全漏洞,该漏洞源于初始化函数与契约创建分离调用(最显著的例子是最小代理),如果它们进行不可信的非视图外部调用,则可以重新输入。一旦初始化器完成运行,它就永远不能被重新执行。然而,支持多继承的异常使可重入成为可能,打破了单次执行的期望。
CVSS Information
N/A
Vulnerability Type
N/A