code-423n4 / 2021-10-union-findings

0 stars 0 forks source link

UToken.__UToken_init can be frontrun #97

Open code423n4 opened 3 years ago

code423n4 commented 3 years ago

Handle

pants

Vulnerability details

The function __UToken_init can be frontrun. We recommend adding an initializer owner which only it allowed to call such functions, instead of the current _admin there.

Not sure whether frontrunning is Low / Medium risk.

GalloDaSballo commented 3 years ago

Agree given the specifics of the sponsor, downgrading to low as the mitigation is to re-deploy