RustFund

First Flight #36
Beginner FriendlyRust
100 EXP
View results
Submission Details
Severity: medium
Valid

Deadline Set Flag Not Updated

Summary

The dealine_set flag (typo in field name) is never updated, allowing multiple deadline modifications.

Vulnerability Details

  1. Typo in dealine_set field (should be deadline_set)

  2. The set_deadline function never sets this flag to true, allowing repeated calls to modify the deadline.

Impact

Creators can arbitrarily extend campaign deadlines, potentially trapping contributor funds indefinitely.

Tools Used

Manual code review

Recommendations

  1. Rename field to deadline_set

  2. Update flag in set_deadline

fund.deadline_set = true;
Updates

Appeal created

bube Lead Judge 5 months ago
Submission Judgement Published
Validated
Assigned finding tags:

Deadline set flag is not updated in `set_deadline` function

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.