missing authorization controll over GaugeController::distributeRewards function
There is no authorization controll over in gaugecontroller::distributeRewars function, therefore anyone can call this function which will call gauge::notifyRewardAmount to change the state of Gauge (e.g the rewardRate).
break the protocol's reward distribution mechanism
manual
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.