Junglewise Threat Intelligence

CVE-2023-26488: OpenZeppelin Contracts incorrect balance calculation in ERC721Consecutive

CVE-2023-26488 · Severity: low · CVSS 3.1 · Published 2023-03-03

Technologies: OpenZeppelin Contracts, @openzeppelin/contracts (npm), OpenZeppelin Contracts Upgradeable, @openzeppelin/contracts-upgradeable (npm). Vendors: OpenZeppelin, npm.

Executive brief

OpenZeppelin Contracts is a widely-used library for building smart contracts on blockchain platforms. The ERC721Consecutive component, which handles batch minting of non-fungible tokens (NFTs), fails to properly update token balances when processing batches of size 1. This can cause balance overflows when tokens are subsequently transferred, allowing attackers to manipulate token balances and potentially steal or duplicate tokens.

Technical details

The vulnerability exists in the ERC721Consecutive contract's batch minting logic, which contains an incorrect calculation that fails to update the balance mapping when a batch contains exactly one token. This issue (CWE-682: Incorrect Calculation) only affects batch size 1. When a single token is minted in a batch, the receiver's balance is not incremented in the balanceOf tracking. Subsequent transfers from the receiver can then cause integer overflow in the balance calculation. The vulnerability affects versions 4.8.0 through 4.8.1 of both @openzeppelin/contracts and @openzeppelin/contracts-upgradeable, and has been patched in version 4.8.2. No authentication is required; any caller able to perform batch minting of size 1 can trigger the flaw.

Affected products

  • OpenZeppelin Contracts >=4.8.0, <4.8.2
  • OpenZeppelin Contracts Upgradeable >=4.8.0, <4.8.2

Timeline

  • 2023-03-03: disclosed: GHSA advisory published
  • 2023-03-03: patched: Fix released in version 4.8.2

References

Related threats