There is no access control to limit who can deploy Escrow contracts via the factory. Any Ethereum address could deploy.
In newEscrow()
, there is no access control.
Anyone could make an Escrow contract
Manual code review
Add a Access Control mechanism to limit the number of addresses to create an Escrow contract
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.