mediumLogic errorEVM-Solidity
Collective: Since art pieces' size is not limited, attacker may block AuctionHouse from creating and settling auctions
- Payout
- $0
- Protocol
- Collective
- Disclosed
- Feb 8, 2024
- Source
- code4rena
The Collective protocol lets any user create art pieces, and the only validation enforced on the submitted metadata is that the metadata fields are non-zero. An attacker can register an art piece carrying a very large data string (roughly one megabyte of null …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2023-12-revolutionprotocol-findings/issues/178
- https://github.com/code-423n4/2023-12-revolutionprotocol-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.