code-423n4 / 2021-12-amun-findings

0 stars 0 forks source link

Missing zero address validation on setRebalanceManager function #295

Open code423n4 opened 2 years ago

code423n4 commented 2 years ago

Handle

Dravee

Vulnerability details

Impact

Losing forever the onlyRebalanceManager privilege

Proof of Concept

A zero address validation is missing on the setRebalanceManager function in the following contracts:

Tools Used

VS Code

loki-sama commented 2 years ago

Setting to any unintended value would have the same effect.

0xleastwood commented 2 years ago

Not an issue, marking as non-critical.