stake.link

stake.link
DeFiHardhatBridge
27,500 USDC
View results
Submission Details
Severity: low
Invalid

Known vulnerabilities in current @openzeppelin/contracts/contracts-upgradeable versions

Summary

The smart contracts relies on outdated versions of the OpenZeppelin contracts library, which are known to contain vulnerabilities.

Vulnerability Details

Given the presence of known vulnerabilities in the current @openzeppelin/contracts version, it is advisable to update to at least @openzeppelin/contracts@5.0.1 to address these issues and enhance the contract's security

Openzeppelin/contracts-upgradeable known vulnerabilities

"@openzeppelin/contracts": "^4.7.0",
"@openzeppelin/contracts-upgradeable": "^4.9.2",

Impact

Using contracts with known vulnerabilities can lead to a wide range of attacks, depending on the nature of the vulnerabilities.

Tools Used

Manual Review

Recommendations

Consider updating to @openzeppelin/contracts@5.0.1 and @openzeppelin/contracts-upgradeable@5.0.1

Updates

Lead Judging Commences

0kage Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.