code-423n4 / 2022-04-abranft-findings

0 stars 0 forks source link

Missing zero address check on _requestLoan #156

Closed code423n4 closed 2 years ago

code423n4 commented 2 years ago

Lines of code

https://github.com/code-423n4/2022-04-abranft/blob/5cd4edc3298c05748e952f8a8c93e42f930a78c2/contracts/NFTPair.sol#L209 https://github.com/code-423n4/2022-04-abranft/blob/5cd4edc3298c05748e952f8a8c93e42f930a78c2/contracts/NFTPairWithOracle.sol#L229

Vulnerability details

Issue: No zero address check for to Consequences: Irrecoverable loss of the collateral NFT.

Proof of Concept

Mitigations

Add zero address check.

cryptolyndon commented 2 years ago

Duplicate of #91

0xean commented 2 years ago

Non critical. marking as dupe of the wardens QA report #137