InsureDAO contest - robee's results

Anyone can create an insurance pool like Uniswap.

General Information

Platform: Code4rena

Start Date: 07/01/2022

Pot Size: $80,000 USDC

Total HM: 21

Participants: 37

Period: 7 days

Judge: 0xean

Total Solo HM: 14

Id: 71

League: ETH

InsureDAO

Findings Distribution

Researcher Performance

Rank: 10/37

Findings: 4

Award: $1,597.61

🌟 Selected for report: 9

🚀 Solo Findings: 0

Findings Information

🌟 Selected for report: Dravee

Also found by: Fitraldys, Ruhum, WatchPug, danb, egjlmn1, robee

Labels

bug
duplicate
2 (Med Risk)

Awards

86.5379 INSURE - $30.29

52.5409 USDC - $52.54

External Links

Handle

robee

Vulnerability details

The attacker can push unlimitedly to an array, that some function loop over this array. If increasing the array size enough, calling the function that does a loop over the array will always revert since there is a gas limit. This is an High Risk issue since those arrays are publicly allows to push items into them.

PoolTemplate.sol (L670): Unbounded loop on the array indexList that can be publicly pushed by ['allocateCredit'] PoolTemplate.sol (L702): Unbounded loop on the array indexList that can be publicly pushed by ['allocateCredit']

#1 - oishun1112

2022-01-12T06:18:39Z

sponsor duplicated

#2 - 0xean

2022-01-27T21:37:43Z

dupe of #352

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter