admin can lock funds #11
Labels
2 (Med Risk)
Assets not at direct risk, but function/availability of the protocol could be impacted or leak value
bug
Something isn't working
duplicate
This issue or pull request already exists
sponsor acknowledged
Technically the issue is correct, but we're not going to resolve it for XYZ reasons
Lines of code
https://github.com/code-423n4/2022-05-rubicon/blob/8c312a63a91193c6a192a9aab44ff980fbfd7741/contracts/rubiconPools/BathHouse.sol#L216-L229
Vulnerability details
description
using the adminWriteBathToken function in BathHouse.sol, the admin can arbitrarily change the bath token address. If done maliciously can lock underlying funds of users who have deposited into that bath token
The text was updated successfully, but these errors were encountered: