code-423n4 / contracts

Code4rena contracts
32 stars 6 forks source link

Use latest OZ dependency to patch DoS vuln for proposal creation #46

Open HickupHH3 opened 1 year ago

HickupHH3 commented 1 year ago

Upgrading Governor due to a security advisory: https://github.com/OpenZeppelin/openzeppelin-contracts/security/advisories/GHSA-5h3x-9wvq-w4m2

While the likelihood of DoS-ing proposal creations is low with marginal benefit to the attacker, the upgrade is recommended out of caution.