Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1704 | OpenZeppelin Contracts is a library for smart contract development. By frontrunning the creation of a proposal, an attacker can become the proposer and gain the ability to cancel it. The attacker can do this repeatedly to try to prevent a proposal from being proposed at all. This impacts the `Governor` contract in v4.9.0 only, and the `GovernorCompatibilityBravo` contract since v4.3.0. This problem has been patched in 4.9.1 by introducing opt-in frontrunning protection. Users are advised to upgrade. Users unable to upgrade may submit the proposal creation transaction to an endpoint with frontrunning protection as a workaround. |
Github GHSA |
GHSA-5h3x-9wvq-w4m2 | OpenZeppelin Contracts's governor proposal creation may be blocked by frontrunning |
Thu, 06 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-06T16:55:49.744Z
Reserved: 2023-05-31T13:51:51.169Z
Link: CVE-2023-34234
Updated: 2024-08-02T16:01:54.273Z
Status : Modified
Published: 2023-06-07T18:15:09.977
Modified: 2024-11-21T08:06:49.623
Link: CVE-2023-34234
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA