Lender can front-run borrwer to reduce auction length.
When a borrower borrows a loan, the borrower can only specify poolId, debt and collateral , but cannot specify the auction length:
This is problematic as lender can front-run and reduce the auction length.
This can be done by calling setPool(…) function.
Loan can be seized in a very short period of time before borrower can react and repay is auction length is very short.
Manual Review
Borrower should be allowed to specify interest rate and auction length when borrowing, transaction should be revert if the pool's interest rate or aution length is not as expected.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.