We found results for “”
CVE-2023-34234
Good to know:
Date: June 7, 2023
OpenZeppelin Contracts is a library for smart contract development. By frontrunning the creation of a proposal, an attacker can become the proposer and gain the ability to cancel it. The attacker can do this repeatedly to try to prevent a proposal from being proposed at all. This impacts the `Governor` contract in v4.9.0 only, and the `GovernorCompatibilityBravo` contract since v4.3.0. This problem has been patched in 4.9.1 by introducing opt-in frontrunning protection. Users are advised to upgrade. Users unable to upgrade may submit the proposal creation transaction to an endpoint with frontrunning protection as a workaround.
Language: JS
Severity Score
Related Resources (7)
Severity Score
Weakness Type (CWE)
Insufficient Information
NVD-CWE-noinfoMissing Authorization
CWE-862Top Fix
Upgrade Version
Upgrade to version @openzeppelin/contracts-upgradeable - 4.9.1;@openzeppelin/contracts - 4.9.1
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | NONE |
Integrity (I): | NONE |
Availability (A): | LOW |