High severity7.5NVD Advisory· Published Feb 18, 2022· Updated Jun 17, 2026
CVE-2022-25335
CVE-2022-25335
Description
RigoBlock Dragos through 2022-02-17 lacks the onlyOwner modifier for setMultipleAllowances. This enables token manipulation, as exploited in the wild in February 2022. NOTE: although 2022-02-17 is the vendor's vulnerability announcement date, the vulnerability will not be remediated until a major protocol upgrade occurs.
Affected products
2- RigoBlock/Dragosdescription
Patches
Vulnerability mechanics
References
5- raw.globalsecuritydatabase.org/GSD-2022-1000077nvdExploitThird Party Advisory
- twitter.com/RigoBlock/status/1494351180713050116nvdExploitIssue TrackingThird Party Advisory
- twitter.com/danielvf/status/1494317265835147272nvdExploitIssue TrackingThird Party Advisory
- etherscan.io/contractdiffcheckernvdProductThird Party Advisory
- etherscan.io/tx/0x5a6c108d5a729be2011cd47590583a04444d4e7c85cd0427071b968edc3bfc1fnvdThird Party Advisory
News mentions
0No linked articles in our index yet.