sherlock-audit / 2024-05-kwenta-x-perennial-integration-update-judging

5 stars 3 forks source link

kaancaglan - Vulnerable versions of packages are being used #29

Closed sherlock-admin2 closed 5 months ago

sherlock-admin2 commented 5 months ago

kaancaglan

medium

Vulnerable versions of packages are being used

Summary

This project is using specific package versions which are vulnerable to the specific CVEs listed below. Consider switching to more recent versions of these packages that don't have these vulnerabilities.

Vulnerability Detail

Impact

All impacts are explained above.

Code Snippet

"@openzeppelin/contracts": "4.8.0",

Github Link

Tool used

Manual Review

Recommendation

Consider updating packages to safest version.

sherlock-admin4 commented 5 months ago

2 comment(s) were left on this issue during the judging contest.

z3s commented:

Low/Info; No attack showed.

FSchmoede commented:

Considered low or informational severity.