MEDIUMcrates.io →
ink! vulnerable to incorrect decoding of storage value when using `DelegateCall`
ink! vulnerable to incorrect decoding of storage value when using `DelegateCall`
Affected packages
- ink
- ink_env
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/paritytech/ink/security/advisories/GHSA-853p-5678-hv8f
- https://nvd.nist.gov/vuln/detail/CVE-2023-34449
- https://github.com/paritytech/ink/pull/1450
- https://github.com/paritytech/ink/commit/f1407ee9f87e5f64d467a22d26ee88f61db7f3db
- https://docs.rs/ink_env/4.2.0/ink_env/call/struct.CallBuilder.html#method.delegate
- https://docs.rs/ink_env/4.2.0/ink_env/fn.invoke_contract_delegate.html
- https://github.com/paritytech/ink
Structured record: https://osv.dev/vulnerability/GHSA-853p-5678-hv8f
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta