MEDIUM5.9
GHSA-699g-q6qh-q4v8
OpenZeppelin Contracts and Contracts Upgradeable duplicated execution of subcalls in v4.9.4
Quick fix
GHSA-699g-q6qh-q4v8 — @openzeppelin/contracts: upgrade to the fixed version with the command below.
npm install @openzeppelin/contracts@4.9.5Details
### Context Merge conflict resolution issue when porting the v5.0.1 `Multicall` update to the v4.9 branch caused a duplicated line.
### Impact Versions using `Multicall` from `@openzeppelin/contracts@4.9.4` and `@openzeppelin/contracts-upgradeable@4.9.4` will execute each subcall twice. Concretely, this exposes a user to unintentionally duplicate operations like asset transfers.
### Patches The duplicated `delegatecall` was removed in 4.9.5. The 4.9.4 version is marked as deprecated.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/@openzeppelin/contracts
Introduced in:
4.9.4Fixed in: 4.9.5Fix
npm install @openzeppelin/contracts@4.9.5npm/@openzeppelin/contracts-upgradeable
Introduced in:
4.9.4Fixed in: 4.9.5Fix
npm install @openzeppelin/contracts-upgradeable@4.9.5References
- https://github.com/OpenZeppelin/openzeppelin-contracts/security/advisories/GHSA-699g-q6qh-q4v8[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-49798[ADVISORY]
- https://github.com/OpenZeppelin/openzeppelin-contracts-upgradeable/commit/31f9fb9d171f60b2271b2b9c6f62d43302bf9489[WEB]
- https://github.com/OpenZeppelin/openzeppelin-contracts/commit/88ac712e06832bce73b41e8166cded2729e25205[WEB]
- https://github.com/OpenZeppelin/openzeppelin-contracts[PACKAGE]