CVE-2023-34459: OpenZeppelin Contracts's MerkleProof multiproofs may allow proving arbitrary leaves for specific trees

Published Jun 16, 2023
·
Updated

Impact

When the verifyMultiProof, verifyMultiProofCalldata, processMultiProof, or processMultiProofCalldata functions are in use, it is possible to construct merkle trees that allow forging a valid multiproof for an arbitrary set of leaves.

A contract may be vulnerable if it uses multiproofs for verification and the merkle tree that is processed includes a node with value 0 at depth 1 (just under the root). This could happen inadvertently for balanced trees with 3 leaves or less, if the leaves are not hashed. This could happen deliberately if a malicious tree builder includes such a node in the tree.

A contract is not vulnerable if it uses single-leaf proving (verify, verifyCalldata, processProof, or processProofCalldata), or if it uses multiproofs with a known tree that has hashed leaves. Standard merkle trees produced or validated with the @openzeppelin/merkle-tree library are safe.

Patches

The problem has been patched in 4.9.2.

Workarounds

If you are using multiproofs: When constructing merkle trees hash the leaves and do not insert empty nodes in your trees. Using the @openzeppelin/merkle-tree package eliminates this issue. Do not accept user-provided merkle roots without reconstructing at least the first level of the tree. Verify the merkle tree structure by reconstructing it from the leaves.

Other sources

OpenZeppelin Contracts is a library for smart contract development. Starting in version 4.7.0 and prior to version 4.9.2, when the verifyMultiProof, verifyMultiProofCalldata, procesprocessMultiProof, or processMultiProofCalldat functions are in use, it is possible to construct merkle trees that allow forging a valid multiproof for an arbitrary set of leaves.

A contract may be vulnerable if it uses multiproofs for verification and the merkle tree that is processed includes a node with value 0 at depth 1 (just under the root). This could happen inadvertedly for balanced trees with 3 leaves or less, if the leaves are not hashed. This could happen deliberately if a malicious tree builder includes such a node in the tree.

A contract is not vulnerable if it uses single-leaf proving (verify, verifyCalldata, processProof, or processProofCalldata), or if it uses multiproofs with a known tree that has hashed leaves. Standard merkle trees produced or validated with the @openzeppelin/merkle-tree library are safe.

The problem has been patched in version 4.9.2.

Some workarounds are available. For those using multiproofs: When constructing merkle trees hash the leaves and do not insert empty nodes in your trees. Using the @openzeppelin/merkle-tree package eliminates this issue. Do not accept user-provided merkle roots without reconstructing at least the first level of the tree. Verify the merkle tree structure by reconstructing it from the leaves.

Affected Software

4 affected componentsFixes available
npm/@openzeppelin/contracts-upgradeable>=4.7.0<4.9.2
4.9.2
npm/@openzeppelin/contracts>=4.7.0<4.9.2
4.9.2
OpenZeppelin Contracts Node.js>=4.7.0<4.9.2
OpenZeppelin Contracts Upgradeable Node.js>=4.7.0<4.9.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@openzeppelin/contracts-upgradeable to a version that resolves this vulnerability.

    Fixed in 4.9.2
  2. Upgrade

    Upgrade npm/@openzeppelin/contracts to a version that resolves this vulnerability.

    Fixed in 4.9.2
  3. Upgrade

    Upgrade OpenZeppelin Contracts to a version that resolves this vulnerability.

    Fixed in 4.9.2
  4. Configuration

    For contracts using verifyMultiProof/verifyMultiProofCalldata/processMultiProof/processMultiProofCalldata, construct the merkle tree by hashing the leaves and do not insert empty nodes; ensure the processed multiproof tree does not include a node with value 0 at depth 1.

    Merkle proof verification (OpenZeppelin Contracts MerkleProof) multiproof tree construction (hash leaves / avoid empty node at depth 1) = Use hashed leaves and ensure the merkle tree does not include a node with value 0 at depth 1 (just under the root)
  5. Compensating control

    Do not accept user-provided merkle roots without reconstructing at least the first level of the tree (verify the merkle tree structure by reconstructing it from the leaves).

  6. Compensating control

    If possible, produce/validate the merkle trees using the @openzeppelin/merkle-tree library to eliminate the forging issue.

Event History

Jun 16, 2023
CVE Published
via MITRE·10:13 PM
Data Sourced
via MITRE·10:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 19, 2023
Advisory Published
07:46 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the vulnerability associated with CVE-2023-34459?

The vulnerability associated with CVE-2023-34459 is related to OpenZeppelin Contracts version 4.7.0 to 4.9.2 and allows for the construction of malicious Merkle trees.

2

How does the vulnerability in OpenZeppelin Contracts manifest?

The vulnerability manifests when using the `verifyMultiProof`, `verifyMultiProofCalldata`, `procesprocessMultiProof`, or `processMultiProofCalldat` functions in OpenZeppelin Contracts versions 4.7.0 to 4.9.2.

3

What is the severity of the OpenZeppelin Contracts vulnerability (CVE-2023-34459)?

The severity of the OpenZeppelin Contracts vulnerability (CVE-2023-34459) is medium with a CVSS score of 5.9.

4

Which versions of OpenZeppelin Contracts are affected by the vulnerability?

OpenZeppelin Contracts versions 4.7.0 to 4.9.2 are affected by the vulnerability.

5

How can I fix the vulnerability in OpenZeppelin Contracts?

To fix the vulnerability in OpenZeppelin Contracts, you should update to version 4.9.2 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203