7.5

CVE-2022-48216

Exploit
Uniswap Universal Router before 1.1.0 mishandles reentrancy. This would have allowed theft of funds.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
UniswapUniversal Router Firmware Version < 1.1.0
   UniswapUniversal Router Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.76% 0.504
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-667 Improper Locking

The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.

https://github.com/Uniswap/universal-router/commit/d82c6685ef566d9b280651c99f4b93a8454c08a8
Patch
Third Party Advisory
https://github.com/Uniswap/universal-router/compare/v1.0.1...v1.1.0
Third Party Advisory
Release Notes
https://github.com/Uniswap/universal-router/pull/189
Patch
Third Party Advisory
https://media.dedaub.com/uniswap-bug-bounty-1625d8ff04ae
Third Party Advisory
Exploit
https://twitter.com/dedaub/status/1610058814094450694
Third Party Advisory