Dandy Caramel Tortoise - Attacker can revoke any user from a market #37
Labels
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
Dandy Caramel Tortoise
Medium
Attacker can revoke any user from a market
Summary
Lack of access control in
revokeLender
allows an attacker to revoke any participant from a marketRoot Cause
The delegation version of the
revokeLender
function fails to perform any access control checks allowing any user to revoke any userInternal pre-conditions
Attestation should be enabled to observe the impact
External pre-conditions
No response
Attack Path
revokeLender
by passing in any address they wish to revoke from the marketImpact
Attacker can revoke any address they wish from any market making the market unuseable
PoC
No response
Mitigation
Perform access control checks
The text was updated successfully, but these errors were encountered: