In the PreMarkets::listOffer
function the below code incorrectly uses memory
instead of storage
for the originOfferInfo
struct when updating the originOfferInfo.abortOfferStatus
to SubOfferListed
.
The state update for originOfferInfo.abortOfferStatus
will not be reflected in the storage.
The origin offer status will be SubOfferListed
within the function, meaning it will not reflected for other functions.
Manual review.
Replace memory
with storage
.
Valid high severity, because the `abortOfferStatus` of the offer is not updated and persist through `storage` when listing an offer for turbo mode within the `offerInfoMap` mapping, it allows premature abortion given the `abortOfferStatus` defaults to `Initialized`, allowing the bypass of this [check](https://github.com/Cyfrin/2024-08-tadle/blob/04fd8634701697184a3f3a5558b41c109866e5f8/src/core/PreMarkets.sol#L552-L557) here and allow complete refund of initial collateral + stealing of trade tax which can potentially be gamed for profits using multiple addresses
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.