code-423n4 / 2024-09-reserve-mitigation-findings

0 stars 0 forks source link

ADD-01 MitigationConfirmed #18

Open c4-bot-3 opened 2 months ago

c4-bot-3 commented 2 months ago

The provided change fully fixes the finding Governance can bypass DAO fee through custom EasyAuction implementation without introducing regressions.

EasyAuction implementations are now hardwired in the GnosisTrade contract implementation, which constitutes a good trade-off between:

The change therefore lifts the EasyAuction setting from a lower security that allows Governance to change it freely, to the same level that is given to contract upgrades, and this is consistent with all actions that Governance can take to avoid paying fees.

The EasyAuction implementation being used is now one deployed by the sponsor. This contract is identical to the original EasyAuction implementation and no issues were found with it or its deployment parameters.

c4-judge commented 2 months ago

thereksfour marked the issue as satisfactory

c4-judge commented 2 months ago

thereksfour marked the issue as confirmed for report