address(0)
can be passed to either one of the collections which can cause a loss of assets.
If admin passes address(0)
as an argument to one of the mappings, for example, collection_l2
, this will deploy new ERC721
instead of using the old one.
address(0)
can be passed to mapping
Manual Review
add check preventing admin for providing address(0)
as mapping value.
Please, do not suppose impacts, think about the real impact of the bug and check the CodeHawks documentation to confirm: https://docs.codehawks.com/hawks-auditors/how-to-determine-a-finding-validity A PoC always helps to understand the real impact possible.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.