CVE-2024-32645

Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, incorrect values can be logged when `raw_log` builtin is called with memory or storage arguments to be used as topics. A contract search was performed and no vulnerable contracts were found in production. The `build_IR` function of the `RawLog` class fails to properly unwrap the variables provided as topics. Consequently, incorrect values are logged as topics. As of time of publication, no fixed version is available.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vyperlang:vyper:*:*:*:*:*:python:*:*

History

02 Jan 2025, 22:52

Type Values Removed Values Added
First Time Vyperlang
Vyperlang vyper
References () https://github.com/vyperlang/vyper/security/advisories/GHSA-xchq-w5r3-4wg3 - () https://github.com/vyperlang/vyper/security/advisories/GHSA-xchq-w5r3-4wg3 - Vendor Advisory
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:vyperlang:vyper:*:*:*:*:*:python:*:*

21 Nov 2024, 09:15

Type Values Removed Values Added
References () https://github.com/vyperlang/vyper/security/advisories/GHSA-xchq-w5r3-4wg3 - () https://github.com/vyperlang/vyper/security/advisories/GHSA-xchq-w5r3-4wg3 -
Summary
  • (es) Vyper es un lenguaje de contrato inteligente pitónico para la máquina virtual Ethereum. En las versiones 0.3.10 y anteriores, se pueden registrar valores incorrectos cuando se llama al comando interno `raw_log` con argumentos de memoria o almacenamiento para usar como temas. Se realizó una búsqueda de contratos y no se encontraron contratos vulnerables en producción. La función `build_IR` de la clase `RawLog` no desenvuelve correctamente las variables proporcionadas como temas. En consecuencia, los valores incorrectos se registran como temas. Al momento de la publicación, no hay ninguna versión fija disponible.

25 Apr 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-25 18:15

Updated : 2025-01-02 22:52


NVD link : CVE-2024-32645

Mitre link : CVE-2024-32645

CVE.ORG link : CVE-2024-32645


JSON object : View

Products Affected

vyperlang

  • vyper
CWE
CWE-20

Improper Input Validation

NVD-CWE-noinfo