GHSA-93hq-5wgc-jc82
GovernorCompatibilityBravo may trim proposal calldata
Quick fix
GHSA-93hq-5wgc-jc82 — @openzeppelin/contracts: upgrade to the fixed version with the command below.
npm install @openzeppelin/contracts@4.8.3Details
### Impact
The proposal creation entrypoint (`propose`) in `GovernorCompatibilityBravo` allows the creation of proposals with a `signatures` array shorter than the `calldatas` array. This causes the additional elements of the latter to be ignored, and if the proposal succeeds the corresponding actions would eventually execute without any calldata. The `ProposalCreated` event correctly represents what will eventually execute, but the proposal parameters as queried through `getActions` appear to respect the original intended calldata.
### Patches
This issue has been patched in v4.8.3.
### Workarounds
Ensure that all proposals that pass through governance have equal length `signatures` and `calldatas` parameters.
Are you affected?
Enter the version of the package you're using.
Affected packages
4.3.0Fixed in: 4.8.3npm install @openzeppelin/contracts@4.8.34.3.0Fixed in: 4.8.3npm install @openzeppelin/contracts-upgradeable@4.8.3References
- https://github.com/OpenZeppelin/openzeppelin-contracts/security/advisories/GHSA-93hq-5wgc-jc82[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-30542[ADVISORY]
- https://github.com/OpenZeppelin/openzeppelin-contracts/commit/8d633cb7d169f2f8595b273660b00b69e845c2fe[WEB]
- https://github.com/OpenZeppelin/openzeppelin-contracts[PACKAGE]
- https://github.com/OpenZeppelin/openzeppelin-contracts/releases/tag/v4.8.3[WEB]