The auctionEnd() function is accessible to everyone after the auction contract is created, meaning that anyone can call it and end the auction at any chosen moment. All functions affecting the course of the auction should be secured with appropriate access controls.
Anyone can end the auction after its allotted time has expired.
Anyone can end the auction after its allotted time has expired.
Manual Review, Foundry
You should add an Access Control mechanism to the auctionEnd function so that the decision to end the auction is reserved exclusively for the auction owner.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.