CVE-2023-34234: Governor proposal creation may be blocked by frontrunning in OpenZeppelin

Published Jun 7, 2023
·
Updated

Impact

By frontrunning the creation of a proposal, an attacker can become the proposer and gain the ability to cancel it. The attacker can do this repeatedly to try to prevent a proposal from being proposed at all.

This impacts the Governor contract in v4.9.0 only, and the GovernorCompatibilityBravo contract since v4.3.0.

Patches

The problem has been patched in 4.9.1 by introducing opt-in frontrunning protection.

Workarounds

Submit the proposal creation transaction to an endpoint with frontrunning protection.

Credit

Reported by Lior Abadi and Joaquin Pereyra from Coinspect.

References

https://www.coinspect.com/openzeppelin-governor-dos/

Other sources

OpenZeppelin Contracts is a library for smart contract development. By frontrunning the creation of a proposal, an attacker can become the proposer and gain the ability to cancel it. The attacker can do this repeatedly to try to prevent a proposal from being proposed at all. This impacts the Governor contract in v4.9.0 only, and the GovernorCompatibilityBravo contract since v4.3.0. This problem has been patched in 4.9.1 by introducing opt-in frontrunning protection. Users are advised to upgrade. Users unable to upgrade may submit the proposal creation transaction to an endpoint with frontrunning protection as a workaround.

Affected Software

4 affected componentsFixes available
npm/@openzeppelin/contracts-upgradeable>=4.3.0<4.9.1
4.9.1
npm/@openzeppelin/contracts>=4.3.0<4.9.1
4.9.1
OpenZeppelin Contracts Node.js>=4.3.0<4.9.1
OpenZeppelin Contracts Upgradeable Node.js>=4.3.0<4.9.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@openzeppelin/contracts-upgradeable to a version that resolves this vulnerability.

    Fixed in 4.9.1
  2. Upgrade

    Upgrade npm/@openzeppelin/contracts to a version that resolves this vulnerability.

    Fixed in 4.9.1
  3. Upgrade

    Upgrade OpenZeppelin Contracts Governor to a version that resolves this vulnerability.

    Fixed in 4.9.1
  4. Compensating control

    For Governor contract instances that cannot be upgraded (affected in v4.9.0 and GovernorCompatibilityBravo since v4.3.0), submit the proposal creation transaction to an endpoint with frontrunning protection.

Event History

Jun 7, 2023
CVE Published
via MITRE·05:06 PM
Data Sourced
via MITRE·05:06 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 8, 2023
Advisory Published
06:03 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2023-34234?

CVE-2023-34234 is a vulnerability in the OpenZeppelin Contracts library that allows an attacker to frontrun the creation of a proposal and cancel it, potentially preventing the proposal from being proposed at all.

2

How does CVE-2023-34234 impact OpenZeppelin Contracts?

CVE-2023-34234 impacts OpenZeppelin Contracts by allowing an attacker to become the proposer of a proposal and gain the ability to cancel it repeatedly, potentially disrupting the proposal process.

3

What is the severity of CVE-2023-34234?

CVE-2023-34234 has a severity level of 5.3 (Medium).

4

Which software versions are affected by CVE-2023-34234?

OpenZeppelin Contracts versions 4.3.0 to 4.9.1 and OpenZeppelin Contracts Upgradeable versions 4.3.0 to 4.9.1 are affected by CVE-2023-34234.

5

How can I mitigate CVE-2023-34234?

To mitigate CVE-2023-34234, it is recommended to update to a version of OpenZeppelin Contracts or OpenZeppelin Contracts Upgradeable that is not affected by the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203