#VU66781 undefined in OpenZeppelin Contracts - CVE-2022-35916
Published: August 26, 2022
OpenZeppelin Contracts
OpenZeppelin
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to contracts using the cross chain utilies for Arbitrum L2, "CrossChainEnabledArbitrumL2" or "LibArbitrumL2", will classify direct interactions of externally owned accounts (EOAs) as cross chain calls, even though they are not started on L1. A remote attacker can perform arbitrary action on the system.