DeFiLayer 1Layer 2
14,723 OP
Submission Details
Severity: high
Invalid

Lack of Access Control on Critical Oracle Update Functions

Author Revealed upon completion
Updates

Lead Judging Commences

0xnevi Lead Judge
about 1 month ago
0xnevi Lead Judge 12 days ago
Submission Judgement Published
Invalidated
Reason: Out of scope
Assigned finding tags:

[invalid] finding-verify-functions-lack-access-control

Invalid, all state roots and proofs must be verified by the OOS `StateProofVerifier` inherited as `Verifier`, so there is no proof that a permisionless `verify`functions allow updating malicious prices

Support

FAQs

Can’t find an answer? Join our Discord or follow us on Twitter.

Cyfrin
Updraft
CodeHawks
Solodit
Resources