code-423n4 / 2023-11-kelp-findings

13 stars 11 forks source link

LRTDepositPool.getAssetDistributionData() - external calls inside loop #138

Closed c4-submissions closed 11 months ago

c4-submissions commented 11 months ago

Lines of code

https://github.com/code-423n4/2023-11-kelp/blob/c5fdc2e62c5e1d78769f44d6e34a6fb9e40c00f0/src/LRTDepositPool.sol#L83-L84

Vulnerability details

Impact

External calls inside a loop might lead to a denial-of-service attack.

Proof of Concept

Tools Used

Slither

Recommended Mitigation Steps

Use try-catch.

Assessed type

DoS

c4-pre-sort commented 11 months ago

raymondfam marked the issue as insufficient quality report

c4-pre-sort commented 11 months ago

raymondfam marked the issue as duplicate of #59

c4-judge commented 10 months ago

fatherGoose1 marked the issue as unsatisfactory: Invalid