Beginner FriendlyFoundryDeFiOracle
100 EXP
View results
Submission Details
Severity: medium
Valid

`OracleUpgradeable::getPriceInWeth` is manipulable because only come from 1 pool

Summary

It's easy to manipulate the price of a pool so a good oracle shouldn't only read the price for a given pool

Vulnerability Details

Couldn't create a scenario in this particular thunderloan project, But usually price oracle manipulation can have huge consequences.

Impact

Could potentially lead to asset loss

Tools Used

read the code

Recommendations

Get a proper price feed from reliable oracle like chainlink oracles

Updates

Lead Judging Commences

0xnevi Lead Judge over 1 year ago
Submission Judgement Published
Validated
Assigned finding tags:

weak oracle

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.