Maia DAO - Ulysses - Viraz's results

Harnessing the power of Arbitrum, Ulysses Omnichain specializes in Virtualized Liquidity Management.

General Information

Platform: Code4rena

Start Date: 22/09/2023

Pot Size: $100,000 USDC

Total HM: 15

Participants: 175

Period: 14 days

Judge: alcueca

Total Solo HM: 4

Id: 287

League: ETH

Maia DAO

Findings Distribution

Researcher Performance

Rank: 144/175

Findings: 1

Award: $11.47

QA:
grade-b

🌟 Selected for report: 0

🚀 Solo Findings: 0

Lines of code

https://github.com/code-423n4/2023-09-maia/blob/main/src/BranchBridgeAgentExecutor.sol#L89 https://github.com/code-423n4/2023-09-maia/blob/main/src/BranchBridgeAgentExecutor.sol#L121 https://github.com/code-423n4/2023-09-maia/blob/main/src/BaseBranchRouter.sol#L146 https://github.com/code-423n4/2023-09-maia/blob/main/src/BaseBranchRouter.sol#L135

Vulnerability details

Impact

In executeWithSettlement & executeWithSettlementMultiple a call to base branch router's methods executeSettlement & executeWithSettlementMultiple are made if the payload length exceeds PARAMS_SETTLEMENT_OFFSET but both methods are not implemented

Proof of Concept

This will cause a DOS situation and not good for the protocol overall

Tools Used

Manual Review

Implement both methods in base branch router

Assessed type

DoS

#0 - c4-pre-sort

2023-10-14T13:35:16Z

0xA5DF marked the issue as sufficient quality report

#1 - c4-pre-sort

2023-10-14T13:35:20Z

0xA5DF marked the issue as primary issue

#2 - 0xA5DF

2023-10-14T13:37:02Z

#318 is the same issue but with MulticallRootRouter

#3 - c4-sponsor

2023-10-17T19:47:55Z

0xLightt (sponsor) disputed

#4 - 0xLightt

2023-10-17T19:49:42Z

This is intended, these functions are not implemented by our base router implementations on purpose. Anyone can build their own router that implements those functions.

#5 - alcueca

2023-10-26T09:09:53Z

User error, unclear docs.

#6 - c4-judge

2023-10-26T09:10:12Z

alcueca changed the severity to QA (Quality Assurance)

#7 - c4-judge

2023-10-26T09:10:17Z

alcueca marked the issue as grade-b

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter