-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| @openzeppelin/contracts | npm | >= 4.3.0, < 4.7.2 | 4.7.2 |
| @openzeppelin/contracts-upgradeable | npm | >= 4.3.0, < 4.7.2 | 4.7.2 |
The analysis involved examining the patches provided for the OpenZeppelin Contracts vulnerability. The key changes were identified in the GovernorVotesQuorumFraction contract, specifically in functions related to calculating and updating the quorum numerator. These changes directly address the vulnerability by ensuring that past proposals are not affected by changes to the quorum requirement.