mintFertilizer
inside calling beanstalkMint
to msg.sender. But their is no access control on mintFertilizer
function so anyone can call this and mint amount of beanstalk to his address.
protocol/contracts/beanstalk/barn/FertilizerFacet.sol#L64-L85
Anyone can call mintFertilizer
and mint amount of beanstalk to his address.
Manual Review
Add some access control to this function so only protocol expected addresses can call this function.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.