Platform: Code4rena
Start Date: 22/08/2022
Pot Size: $50,000 USDC
Total HM: 4
Participants: 160
Period: 5 days
Judge: gzeon
Total Solo HM: 2
Id: 155
League: ETH
Rank: 112/160
Findings: 1
Award: $35.44
🌟 Selected for report: 0
🚀 Solo Findings: 0
🌟 Selected for report: IllIllI
Also found by: 0bi, 0x040, 0x1337, 0x1f8b, 0xDjango, 0xNazgul, 0xNineDec, 0xRajeev, 0xSky, 0xSmartContract, 0xbepresent, 0xkatana, 0xmatt, 8olidity, Aymen0909, Bjorn_bug, Bnke0x0, CertoraInc, Ch_301, Chom, CodingNameKiki, Deivitto, DevABDee, DimitarDimitrov, Dravee, ElKu, Funen, GalloDaSballo, GimelSec, Guardian, Haruxe, JC, JansenC, Jeiwan, JohnSmith, KIntern_NA, Lambda, LeoS, Noah3o6, Olivierdem, R2, RaymondFam, Respx, ReyAdmirado, Rohan16, Rolezn, Ruhum, Saintcode_, Sm4rty, SooYa, Soosh, TomJ, Tomo, Trabajo_de_mates, Waze, _Adam, __141345__, ajtra, android69, asutorufos, auditor0517, berndartmueller, bobirichman, brgltd, c3phas, cRat1st0s, carlitox477, catchup, cccz, csanuragjain, d3e4, delfin454000, dipp, djxploit, durianSausage, erictee, exd0tpy, fatherOfBlocks, gogo, hyh, ladboy233, lukris02, mics, mrpathfindr, natzuu, oyc_109, p_crypt0, pashov, pauliax, pfapostol, prasantgupta52, rajatbeladiya, rbserver, ret2basic, rfa, robee, rokinot, rvierdiiev, sach1r0, saian, seyni, shenwilly, sikorico, simon135, sryysryy, sseefried, throttle, tnevler, tonisives, wagmi, xiaoming90, yixxas, z3s, zkhorse, zzzitron
35.4386 USDC - $35.44
The NounsDAOProxy.sol constructor does not correctly validate passed parameters. This could allow admin_ to be set to address(0), or invalid values could be set for timelock_, nouns_, vetoer_, votingPeriod_, votingDelay_, proposalThresholdBPS_, and quorumVotesBPS_.
The contract should implement bounds checks for key variables. Values such as address(0) or unit256(0) should be rejected. The proposalThresholdBPS_ variable should be checked to ensure it's equal to or greater than MIN_PROPOSAL_THRESHOLD_BPS and is below or equal to MAX_PROPOSAL_THRESHOLD_BPS as defined in NounsDAOLogicv1.sol and NounsDaoLogicv2.sol.
This will reduce the chance of risk through error or omission of parameter values at construction.
Please note that while not checked in the constructor, the implementation_ parameter is checked in the _setImplementation() call later.
Although technically not listed as in scope this also applies to NounsDaoProxyv2.sol with the shift from quorumVoteBPS_ to dynamicQuorumParams_.