This repository has been archived by the owner on Nov 3, 2024. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 13
Issues: sherlock-audit/2024-04-teller-finance-judging
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
pkqs90 - Users can bypass auction mechanism for A valid Medium severity issue
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
LenderCommitmentGroup_Smart
liquidation mechanism for loans that are close to end of loan
Medium
#289
opened Apr 29, 2024 by
sherlock-admin4
CodeWasp - The cycle payment due may span over approx. 2 cycles and block the borrower from paying
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
#285
opened Apr 29, 2024 by
sherlock-admin3
pkqs90 - A valid issue with 1+ other issues describing the same vulnerability
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
LenderCommitmentGroup_Smart.sol
cannot deploy pools with non-string symbol() ERC20s.
Has Duplicates
#269
opened Apr 29, 2024 by
sherlock-admin2
0xadrii - Performing a direct multiplication in This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
_getPriceFromSqrtX96
will overflow for some uniswap pools
Escalation Resolved
#243
opened Apr 29, 2024 by
sherlock-admin3
0xadrii - Not transferring collateral when submitting bids allows malicious users to create honeypot-style attacks
High
A valid High severity issue
Reward
A payout will be made for this issue
Sponsor Disputed
The sponsor disputed this issue's validity
Won't Fix
The sponsor confirmed this issue will not be fixed
#219
opened Apr 29, 2024 by
sherlock-admin3
EgisSecurity - If A valid High severity issue
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
repayLoanCallback
address doesn't implement repayLoanCallback
try/catch won't go into the catch and will revert the tx
High
#178
opened Apr 29, 2024 by
sherlock-admin4
0x73696d616f - A valid issue with 1+ other issues describing the same vulnerability
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
FlashRolloverLoan_G5
will not work for certain tokens due to not setting the approval to 0
after repaying a loan
Has Duplicates
#140
opened Apr 29, 2024 by
sherlock-admin2
0x73696d616f - A valid issue with 1+ other issues describing the same vulnerability
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
FlashRolloverLoan_G5
will fail for LenderCommitmentGroup_Smart
due to CollateralManager
pulling collateral from FlashRolloverLoan_G5
Has Duplicates
#138
opened Apr 29, 2024 by
sherlock-admin3
0x73696d616f - Incorrect selector in A valid issue with 1+ other issues describing the same vulnerability
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
FlashRolloverLoan_G5::_acceptCommitment()
does not match SmartCommitmentForwarder::acceptCommitmentWithRecipient()
Has Duplicates
#135
opened Apr 29, 2024 by
sherlock-admin3
0x3b - A valid issue with 1+ other issues describing the same vulnerability
High
A valid High severity issue
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
_sendOrEscrowFunds
will brick LCG funds causing insolvency
Has Duplicates
#126
opened Apr 29, 2024 by
sherlock-admin3
0x73696d616f - Issue #497 'Add parameter to lender accept bid for MaxMarketFee' from previous audit is still present
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
#125
opened Apr 29, 2024 by
sherlock-admin2
cryptic - This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
LenderCommitmentGroup
pools will have incorrect exchange rate when fee-on-transfer tokens are used
Escalation Resolved
#122
opened Apr 29, 2024 by
sherlock-admin2
jovi - liquidateDefaultedLoanWithIncentive can be gamed to avoid paying loans interest
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A valid High severity issue
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
#121
opened Apr 29, 2024 by
sherlock-admin4
jovi - Malicious borrower can pay each payment and make its own loan default 1 month later
Escalation Resolved
This issue's escalations have been approved/rejected
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
Sponsor Disputed
The sponsor disputed this issue's validity
Won't Fix
The sponsor confirmed this issue will not be fixed
#116
opened Apr 29, 2024 by
sherlock-admin2
0x73696d616f - Interest rate in A valid issue with 1+ other issues describing the same vulnerability
High
A valid High severity issue
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
LenderCommitmentGroup_Smart
may be easily manipulated by depositing, taking a loan and withdrawing
Has Duplicates
#110
opened Apr 29, 2024 by
sherlock-admin2
0x73696d616f - A valid issue with 1+ other issues describing the same vulnerability
High
A valid High severity issue
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
LenderCommitmentGroup_Smart
picks the wrong Uniswap price, allowing borrowing at a discount by swapping before withdrawing
Has Duplicates
#109
opened Apr 29, 2024 by
sherlock-admin4
0x3b - APRs are lower than they should
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
#72
opened Apr 29, 2024 by
sherlock-admin3
0x3b - Utilization math should include A valid issue with 1+ other issues describing the same vulnerability
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
liquidityThresholdPercent
Has Duplicates
#70
opened Apr 29, 2024 by
sherlock-admin4
0x3b - Borrowers can surpass This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Won't Fix
The sponsor confirmed this issue will not be fixed
liquidityThresholdPercent
and borrow to near 100% of the principal
Escalation Resolved
#68
opened Apr 29, 2024 by
sherlock-admin2
0x73696d616f - A valid issue with 1+ other issues describing the same vulnerability
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
LenderCommitmentGroup_Smart_test::addPrincipalToCommitmentGroup/burnSharesToWithdrawEarnings()
are vulnerable to slippage attacks
Has Duplicates
#64
opened Apr 29, 2024 by
sherlock-admin4
0x73696d616f - Drained lender due to A valid issue with 1+ other issues describing the same vulnerability
High
A valid High severity issue
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
LenderCommitmentGroup_Smart::acceptFundsForAcceptBid()
_collateralAmount
by STANDARD_EXPANSION_FACTOR
multiplication
Has Duplicates
#58
opened Apr 29, 2024 by
sherlock-admin4
DenTonylifer - Anyone can steal pool shares from lender group if no-revert-on-failure tokens are used
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A valid High severity issue
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
#50
opened Apr 29, 2024 by
sherlock-admin2
0x3b - liquidateDefaultedLoanWithIncentive sends the collateral to the wrong account
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A valid High severity issue
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
#46
opened Apr 29, 2024 by
sherlock-admin4
0x3b - Borrowers can brick the commitment group pool
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A valid High severity issue
Reward
A payout will be made for this issue
Sponsor Disputed
The sponsor disputed this issue's validity
Won't Fix
The sponsor confirmed this issue will not be fixed
#42
opened Apr 29, 2024 by
sherlock-admin3
0x73696d616f - This issue's escalations have been approved/rejected
Medium
A valid Medium severity issue
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
LenderCommitmentGroup_Smart
does not use mulDiv
when converting between token and share amounts, possibly leading to DoS or loss of funds
Escalation Resolved
#39
opened Apr 29, 2024 by
sherlock-admin3
Previous Next
ProTip!
Type g p on any issue or pull request to go back to the pull request listing page.