Executive brief
OpenZeppelin Contracts is a widely-used library for building secure smart contracts on blockchain platforms. The GovernorCompatibilityBravo module, which implements governance voting and proposal execution, may incorrectly encode function arguments when proposals are created using explicit function signatures. This could cause governance proposals to execute with wrong parameters, potentially resulting in unintended contract state changes or logic execution.
Technical details
The vulnerability exists in the GovernorCompatibilityBravo contract's ABI encoding logic when proposals are created with explicit function signatures (e.g., "foo(uint256)") rather than pre-encoded function selectors. When a proposal is created using the signatures parameter, the contract incorrectly encodes the provided calldata, leading to function calls with incorrect arguments. The attack vector requires local control of proposal creation; no network or authentication bypass is needed. An attacker controlling proposal submission can craft proposals that execute unintended logic. This issue affects versions 4.3.0 through 4.4.1; it was patched in v4.4.2. Proposal creation through the Tally platform or OpenZeppelin Defender is not affected.
Affected products
- OpenZeppelin Contracts 4.3.0 through 4.4.1
- OpenZeppelin Contracts Upgradeable 4.3.0 through 4.4.1
Timeline
- 2022-01-11: disclosed: Advisory published
- 2022-01-13: patched: Version 4.4.2 released with fix