code-423n4 / 2023-11-kelp-findings

13 stars 11 forks source link

does not have a function to remove supported assets #457

Closed c4-submissions closed 11 months ago

c4-submissions commented 11 months ago

Lines of code

https://github.com/code-423n4/2023-11-kelp/blob/main/src/LRTConfig.sol#L94

Vulnerability details

Impact

The contract does not have a function to remove supported assets. If an asset becomes compromised or is no longer needed, there is no way to remove it from the system.

Tools Used

Recommended Mitigation Steps

Assessed type

Context

c4-pre-sort commented 11 months ago

raymondfam marked the issue as insufficient quality report

c4-pre-sort commented 11 months ago

raymondfam marked the issue as duplicate of #38

c4-judge commented 10 months ago

fatherGoose1 changed the severity to QA (Quality Assurance)

c4-judge commented 10 months ago

fatherGoose1 marked the issue as grade-b