createPool
on DistributionV2
lack of role modifier, open for public to create pool
createPool
on DistributionV2 lack of role modifier, thus anyone can create pool, unlike Distribution contract which has onlyOwner
.
This is clearly a missed oversight, opening createPool
accessible by public
Anyone can create pool which is not expected by protocol
Manual analysis
Add onlyOwner
modifier just like Distribution::createPool
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.