cbcvebase.
CVE-2023-34234
published 2023-06-07

CVE-2023-34234: OpenZeppelin Contracts is a library for smart contract development. By frontrunning the creation of a proposal, an attacker can become the proposer and gain…

PriorityP425medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.60%
44.5th percentile
OpenZeppelin Contracts is a library for smart contract development. By frontrunning the creation of a proposal, an attacker can become the proposer and gain the ability to cancel it. The attacker can do this repeatedly to try to prevent a proposal from being proposed at all. This impacts the `Governor` contract in v4.9.0 only, and the `GovernorCompatibilityBravo` contract since v4.3.0. This problem has been patched in 4.9.1 by introducing opt-in frontrunning protection. Users are advised to upgrade. Users unable to upgrade may submit the proposal creation transaction to an endpoint with frontrunning protection as a workaround.

Affected

5 ranges
VendorProductVersion rangeFixed in
openzeppelincontracts>= 4.3.0 < 4.9.14.9.1
openzeppelincontracts>= 4.3.0 < 4.9.14.9.1
openzeppelincontracts-upgradeable>= 4.3.0 < 4.9.14.9.1
openzeppelincontracts_upgradeable>= 4.3.0 < 4.9.14.9.1
openzeppelinopenzeppelin-contracts
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.