The approveCollateralTokenForAave function in AaveDIVAWrapper.sol lacks the onlyOwner modifier, allowing any user to reset Aave V3 allowances for registered collateral tokens.
Location: AaveDIVAWrapper.sol
Code:
Issue: The function is callable by anyone, enabling malicious actors to reset allowances and potentially drain funds if combined with other vulnerabilities.
Critical: An attacker could reset allowances for collateral tokens, leading to unauthorized transfers or fund loss.
Manual code review.
Add the onlyOwner modifier to restrict access:
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.