code-423n4 / 2022-01-yield-findings

1 stars 0 forks source link

Lack of important event #43

Open code423n4 opened 2 years ago

code423n4 commented 2 years ago

Handle

0x1f8b

Vulnerability details

Impact

owner can change the source without any warning.

Proof of Concept

The method Cvx3CrvOracle.setSource should emit an event in order to be able to detect this call by dapps.

Tools Used

Manual review

Recommended Mitigation Steps

Emit an event

GalloDaSballo commented 2 years ago

Agree with the finding, because events are informational in nature, am going to downgrade to non-critical