Oracle data feed is insufficiently validated. #136
Labels
2 (Med Risk)
Assets not at direct risk, but function/availability of the protocol could be impacted or leak value
bug
Something isn't working
resolved
Finding has been patched by sponsor (sponsor pls link to PR containing fix)
sponsor confirmed
Sponsor agrees this is a problem and intends to fix it (OK to use w/ "disagree with severity")
Handle
throttle
Vulnerability details
Impact
Price can be stale and can lead to wrong
quoteAmount
return valueProof of Concept
Oracle data feed is insufficiently validated. There is no check for stale price and round completeness.
Price can be stale and can lead to wrong
quoteAmount
return valueTools Used
Manual review
Recommended Mitigation Steps
Validate data feed
The text was updated successfully, but these errors were encountered: