Junglewise Threat Intelligence

CVE-2022-35916: OpenZeppelin Contracts Arbitrum L2 cross-chain validation bypass

CVE-2022-35916 · Severity: low · CVSS 3.1 · Published 2022-08-14

Technologies: OpenZeppelin Contracts, @openzeppelin/contracts (npm), OpenZeppelin Contracts Upgradeable, @openzeppelin/contracts-upgradeable (npm). Vendors: OpenZeppelin, npm.

Executive brief

OpenZeppelin Contracts is a widely-used Ethereum smart contract library that provides cross-chain utilities for the Arbitrum L2 blockchain. The library incorrectly classifies direct user wallet transactions as cross-chain messages originating from the Ethereum main network, bypassing intended cross-chain security checks. This could allow attackers to call protected functions as if they were legitimate cross-chain operations, potentially bypassing authorization checks designed for cross-chain interactions.

Technical details

The vulnerability exists in the CrossChainEnabledArbitrumL2 and LibArbitrumL2 utilities, which misidentify externally owned account (EOA) calls made directly on Arbitrum L2 as cross-chain calls originating from Ethereum L1. The root cause is improper validation logic that fails to distinguish between genuine cross-chain messages and standard L2 transactions. An unauthenticated network attacker can exploit this by calling protected functions directly on L2, and the contract will incorrectly treat these as cross-chain-initiated calls. The impact is mitigated by the fact that any EOA action taken on L2 could alternatively be performed through the bridge in the absence of this check. The vulnerability was patched in OpenZeppelin Contracts v4.7.2.

Affected products

  • OpenZeppelin Contracts 4.6.0 to 4.7.1
  • OpenZeppelin Contracts Upgradeable 4.6.0 to 4.7.1

Timeline

  • 2022-08-14: disclosed: Vulnerability published
  • 2022-08-14: patched: Fixed in v4.7.2

References

Related threats