CVE-2024-32645: vyper performs incorrect topic logging in raw_log
Incorrect values can be logged when raw_log
builtin is called with memory or storage arguments to be used as topics.
A contract search was performed and no vulnerable contracts were found in production. In particular, no uses of raw_log()
were found at all in production; it is apparently not a well-known function.
References
Detect and mitigate CVE-2024-32645 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →