CVE-2023-34234
Governor proposal creation may be blocked by frontrunning in OpenZeppelin
Record summary
CVE-2023-34234 has a selected CVSS score of 5.3 (medium).
Description
OpenZeppelin Contracts is a library for smart contract development. By frontrunning the creation of a proposal, an attacker can become the proposer and gain the ability to cancel it. The attacker can do this repeatedly to try to prevent a proposal from being proposed at all. This impacts the `Governor` contract in v4.9.0 only, and the `GovernorCompatibilityBravo` contract since v4.3.0. This problem has been patched in 4.9.1 by introducing opt-in frontrunning protection. Users are advised to upgrade. Users unable to upgrade may submit the proposal creation transaction to an endpoint with frontrunning protection as a workaround.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 6, 2025 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
openzeppelin-contractsBrowse OpenZeppelin / openzeppelin-contracts | CVE List | >=4.3.0, < 4.9.1 | affected |
@openzeppelin/contractsBrowse npm / @openzeppelin/contracts | GitHub Advisory | 4.3.0 to < 4.9.1 · Fixed in 4.9.1 | affected |
@openzeppelin/contracts-upgradeableBrowse npm / @openzeppelin/contracts-upgradeable | GitHub Advisory | 4.3.0 to < 4.9.1 · Fixed in 4.9.1 | affected |