The mechanics of RecollateralizationLibP1 library are changed significantly. The previously referenced code segments are not present in the new code now. So the attack vector is nullified. However the RecollateralizationLibP1 still uses the price() output values without validations at some places.
M-20 https://github.com/code-423n4/2023-01-reserve-findings/issues/200
The mechanics of RecollateralizationLibP1 library are changed significantly. The previously referenced code segments are not present in the new code now. So the attack vector is nullified. However the RecollateralizationLibP1 still uses the
price()
output values without validations at some places.These code statements can be re-evaluated again.