code-423n4 / 2021-10-slingshot-findings

0 stars 0 forks source link

ModuleRegistry doesn't support admin change methodology #11

Closed code423n4 closed 2 years ago

code423n4 commented 2 years ago

Handle

pants

Vulnerability details

ModuleRegistry doesn't support admin change methodology. You should do a two steps admin change where the previous admin set a pending admin and the pending admin claims ownership.

tommyz7 commented 2 years ago

I believe it's duplicate of #12