Vulnerability Change Records for CVE-2024-32645
Change History
New CVE Received from GitHub, Inc. 4/25/2024 2:15:08 PM
| Action |
Type |
Old Value |
New Value |
| Added |
Description |
|
Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, incorrect values can be logged when `raw_log` builtin is called with memory or storage arguments to be used as topics. A contract search was performed and no vulnerable contracts were found in production. The `build_IR` function of the `RawLog` class fails to properly unwrap the variables provided as topics. Consequently, incorrect values are logged as topics. As of time of publication, no fixed version is available.
|
| Added |
CVSS V3.1 |
|
GitHub, Inc. AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
| Added |
CWE |
|
GitHub, Inc. CWE-20
|
| Added |
Reference |
|
GitHub, Inc. https://github.com/vyperlang/vyper/security/advisories/GHSA-xchq-w5r3-4wg3 [No types assigned]
|
|