CVE-2022-31153

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-31153
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-31153.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-31153
Aliases
Published
2022-07-15T17:50:14Z
Modified
2025-11-14T13:18:26.799126Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
OpenZeppelin Contracts for Cairo account cannot process transactions on Goerli
Details

OpenZeppelin Contracts for Cairo is a library for contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Version 0.2.0 is vulnerable to an error that renders account contracts unusable on live networks. This issue affects all accounts (vanilla and ethereum flavors) in the v0.2.0 release of OpenZeppelin Contracts for Cairo, which are not whitelisted on StarkNet mainnet. Only goerli deployments of v0.2.0 accounts are affected. This faulty behavior is not observed in StarkNet's testing framework. This bug has been patched in v0.2.1.

Database specific
{
    "cwe_ids": [
        "CWE-664"
    ]
}
References

Affected packages

Git / github.com/openzeppelin/cairo-contracts

Affected ranges

Type
GIT
Repo
https://github.com/openzeppelin/cairo-contracts
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*

0.1.0

v0.*

v0.1.0