code-423n4 / 2024-01-salty-findings

11 stars 6 forks source link

anyone can burn tokens and cause a liquidation and a Dos attack #583

Closed c4-bot-5 closed 9 months ago

c4-bot-5 commented 9 months ago

Lines of code

https://github.com/code-423n4/2024-01-salty/blob/53516c2cdfdfacb662cdea6417c52f23c94d5b5b/src/stable/USDS.sol#L53

Vulnerability details

Impact

can cause user or pool unexpected liquidation when increasing position size. Unfair liquidation for users.

Tools Used

manual

Recommended Mitigation Steps

Add a function modifier to the burnTokensInContract function

Assessed type

Access Control