code-423n4 / 2021-12-defiprotocol-findings

0 stars 0 forks source link

Usage of deprecated safeApprove #175

Closed code423n4 closed 2 years ago

code423n4 commented 2 years ago

Handle

GiveMeTestEther

Vulnerability details

Impact

safeApprove is now deprecate.

Proof of Concept

https://github.com/OpenZeppelin/openzeppelin-contracts/blob/566a774222707e424896c0c390a84dc3c13bdcb2/contracts/token/ERC20/utils/SafeERC20.sol#L38

https://github.com/code-423n4/2021-12-defiprotocol/blob/205d3766044171e325df6a8bf2e79b37856eece1/contracts/contracts/Basket.sol#L274

Tools Used

Recommended Mitigation Steps

As per OpenZepplin documentation “whenever possible, use safeIncreaseAllowance and safeDecreaseAllowance instead”.

frank-beard commented 2 years ago

duplicate of https://github.com/code-423n4/2021-12-defiprotocol-findings/issues/177