Skip to content

OpenZeppelin Contracts contains Improper Verification of Cryptographic Signature

Moderate severity GitHub Reviewed Published Feb 1, 2023 in OpenZeppelin/cairo-contracts • Updated Feb 13, 2023

Package

pip openzeppelin-cairo-contracts (pip)

Affected versions

>= 0.2.0, < 0.6.1

Patched versions

0.6.1

Description

Cause

is_valid_eth_signature is missing a call to finalize_keccak after calling verify_eth_signature.

Impact

As a result, any contract using is_valid_eth_signature from the account library (such as the EthAccount preset) is vulnerable to a malicious sequencer. Specifically, the malicious sequencer would be able to bypass signature validation to impersonate an instance of these accounts.

Risk

In order to exploit this vulnerability, it is required to control a sequencer or prover since they're the ones executing the hints, being able to inject incorrect keccak results.

Today StarkWare is the only party running both a prover or a sequencer, greatly reducing the risk of exploit.

Patches

The issue has been patched in 0.6.1.

For more information

If you have any questions or comments about this advisory:

References

@martriay martriay published to OpenZeppelin/cairo-contracts Feb 1, 2023
Published to the GitHub Advisory Database Feb 2, 2023
Reviewed Feb 2, 2023
Published by the National Vulnerability Database Feb 3, 2023
Last updated Feb 13, 2023

Severity

Moderate
5.3
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
High
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

CVE ID

CVE-2023-23940

GHSA ID

GHSA-626q-v9j4-mcp4
Checking history
See something to contribute? Suggest improvements for this vulnerability.