CVE-2023-34234
published 2023-06-07CVE-2023-34234: OpenZeppelin Contracts is a library for smart contract development. By frontrunning the creation of a proposal, an attacker can become the proposer and gain…
PriorityP425medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.60%
44.5th percentile
OpenZeppelin Contracts is a library for smart contract development. By frontrunning the creation of a proposal, an attacker can become the proposer and gain the ability to cancel it. The attacker can do this repeatedly to try to prevent a proposal from being proposed at all. This impacts the `Governor` contract in v4.9.0 only, and the `GovernorCompatibilityBravo` contract since v4.3.0. This problem has been patched in 4.9.1 by introducing opt-in frontrunning protection. Users are advised to upgrade. Users unable to upgrade may submit the proposal creation transaction to an endpoint with frontrunning protection as a workaround.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openzeppelin | contracts | >= 4.3.0 < 4.9.1 | 4.9.1 |
| openzeppelin | contracts | >= 4.3.0 < 4.9.1 | 4.9.1 |
| openzeppelin | contracts-upgradeable | >= 4.3.0 < 4.9.1 | 4.9.1 |
| openzeppelin | contracts_upgradeable | >= 4.3.0 < 4.9.1 | 4.9.1 |
| openzeppelin | openzeppelin-contracts | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenZeppelin Contracts's governor proposal creation may be blocked by frontrunning
ghsa·2023-06-08
CVE-2023-34234 [MEDIUM] CWE-862 OpenZeppelin Contracts's governor proposal creation may be blocked by frontrunning
OpenZeppelin Contracts's governor proposal creation may be blocked by frontrunning
### Impact
By frontrunning the creation of a proposal, an attacker can become the proposer and gain the ability to cancel it. The attacker can do this repeatedly to try to prevent a proposal from being proposed at all.
This impacts the `Governor` contract in v4.9.0 only, and the `GovernorCompatibilityBravo` contract since v4.3.0.
### Patches
The problem has been patched in 4.9.1 by introducing opt-in frontrunning protection.
### Workarounds
Submit the proposal creation transaction to an endpoint with frontrunning protection.
### Credit
Reported by Lior Abadi and Joaquin Pereyra from Coinspect.
### References
https://www.coinspect.com/openzeppelin-governor-dos/
OSV
OpenZeppelin Contracts's governor proposal creation may be blocked by frontrunning
osv·2023-06-08
CVE-2023-34234 [MEDIUM] OpenZeppelin Contracts's governor proposal creation may be blocked by frontrunning
OpenZeppelin Contracts's governor proposal creation may be blocked by frontrunning
### Impact
By frontrunning the creation of a proposal, an attacker can become the proposer and gain the ability to cancel it. The attacker can do this repeatedly to try to prevent a proposal from being proposed at all.
This impacts the `Governor` contract in v4.9.0 only, and the `GovernorCompatibilityBravo` contract since v4.3.0.
### Patches
The problem has been patched in 4.9.1 by introducing opt-in frontrunning protection.
### Workarounds
Submit the proposal creation transaction to an endpoint with frontrunning protection.
### Credit
Reported by Lior Abadi and Joaquin Pereyra from Coinspect.
### References
https://www.coinspect.com/openzeppelin-governor-dos/
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/OpenZeppelin/openzeppelin-contracts/commit/d9474327a492f9f310f31bc53f38dbea56ed9a57https://github.com/OpenZeppelin/openzeppelin-contracts/security/advisories/GHSA-5h3x-9wvq-w4m2https://github.com/OpenZeppelin/openzeppelin-contracts/commit/d9474327a492f9f310f31bc53f38dbea56ed9a57https://github.com/OpenZeppelin/openzeppelin-contracts/security/advisories/GHSA-5h3x-9wvq-w4m2
2023-06-07
Published