Executive brief
OpenZeppelin Contracts is a widely-used library for building Ethereum smart contracts, particularly governance systems. A flaw in the GovernorCompatibilityBravo component allows proposals to be created with mismatched parameter arrays, causing intended transaction data to be silently discarded during execution. This creates a mismatch between what governance participants approve and what actually executes, potentially allowing actions to run without their expected parameters.
Technical details
The vulnerability is an input validation flaw (CWE-20) in GovernorCompatibilityBravo's propose() function, which fails to validate that the signatures and calldatas arrays have equal length. When signatures is shorter than calldatas, the excess calldata elements are silently trimmed during execution. While the ProposalCreated event correctly reflects the truncated execution, getActions() returns the original, full calldata array, creating an information disclosure and creating discrepancy between governance approval and actual execution. The vulnerability affects versions 4.3.0 through 4.8.2 and is fixed in v4.8.3. The attack requires authorization to create proposals (typically token voting) but no user interaction or network-level privileges.
Affected products
- OpenZeppelin Contracts 4.3.0 through 4.8.2
- OpenZeppelin Contracts Upgradeable 4.3.0 through 4.8.2
Timeline
- 2023-04-13: disclosed: Vulnerability published in GitHub advisory
- 2023-04-20: patched: v4.8.3 released with patch