Fraxlend (Frax Finance) contest - ayeslick's results

Fraxlend: A permissionless lending platform and the final piece of the Frax Finance Defi Trinity.

General Information

Platform: Code4rena

Start Date: 12/08/2022

Pot Size: $50,000 USDC

Total HM: 15

Participants: 120

Period: 5 days

Judge: Justin Goro

Total Solo HM: 6

Id: 153

League: ETH

Frax Finance

Findings Distribution

Researcher Performance

Rank: 81/120

Findings: 1

Award: $45.85

🌟 Selected for report: 0

🚀 Solo Findings: 0

Lines of code

https://github.com/code-423n4/2022-08-frax/blob/main/src/contracts/FraxlendPair.sol#L288 https://github.com/code-423n4/2022-08-frax/blob/main/src/contracts/FraxlendPair.sol#L307

Vulnerability details

Impact

To call the function the operator has to be a borrower/lender. Once added the operator can add or remove whomever he wants.

Proof of Concept

An operator is added to the approvedBorrowers/approvedLenders mapping.

There are 5 other approved borrowers/lenders.

The operator decides to remove those borrowers/lenders then added other addresses under his control.

Only allow the owner to remove/add borrowers/lenders

#0 - amirnader-ghazvini

2022-08-29T19:17:57Z

Duplicate of #157

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter