The caller/owner of FjordAuctionFactory::setOwner
the function should not be authorized to setOwner as they could set themselves as the new owner.
The caller/owner can set themselves as the newOwner of the account with multiple different addresses, this does not allow for proper admin privileges/rights and restrictions to sensitive functions/operation
Highly Probable
Manual Review
Consider using Openzppelin Access Control library/Interface https://docs.openzeppelin.com/contracts/5.x/access-control#using-access-control
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.