code-423n4 / 2021-09-yaxis-findings

0 stars 0 forks source link

Controller: Extra sload of _vaultDetails[_vault].balance #65

Open code423n4 opened 2 years ago

code423n4 commented 2 years ago

Handle

hickuphh3

Vulnerability details

Impact

_vaultDetails[_vault].balance in L367 can be changed to the already fetched value _balance.

Recommended Mitigation Steps

_vaultDetails[_vault].balance = _vaultDetails[_vault].balance.sub(_amount);

GalloDaSballo commented 2 years ago

Sponsor acknowledge and mitigated, LG