DeFiFoundry
20,000 USDC
View results
Submission Details
Severity: low
Invalid

Centralization Risk, Caller/Owner of `FjordAuctionFactory::setOwner` function should not be able to set newOwner

Summary

The caller/owner of FjordAuctionFactory::setOwnerthe function should not be authorized to setOwner as they could set themselves as the new owner.

Vulnerability Details

The caller/owner can set themselves as the newOwner of the account with multiple different addresses, this does not allow for proper admin privileges/rights and restrictions to sensitive functions/operation

Impact

Highly Probable

Tools Used

Manual Review

Recommendations

Consider using Openzppelin Access Control library/Interface https://docs.openzeppelin.com/contracts/5.x/access-control#using-access-control

Updates

Lead Judging Commences

inallhonesty Lead Judge 10 months ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.