CVE-2023-34459 is a medium-severity vulnerability affecting OpenZeppelin Contracts versions 4.7.0 through 4.9.1, specifically when using multiproof verification functions. An attacker can forge valid multiproofs for arbitrary leaves if the Merkle tree contains a node with a zero value at depth one, potentially leading to unauthorized actions. The vulnerability has a CVSS score of 5.9 (Medium) due to its high impact on integrity and low attack complexity, although it requires specific tree constructions. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.7.0, < 4.9.2CPE matchmatch criteria | cpe:2.3:a:openzeppelin:contracts:*:*:*:*:*:node.js:*:* | ||
>= 4.7.0, < 4.9.2CPE matchmatch criteria | cpe:2.3:a:openzeppelin:contracts_upgradeable:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.