highInteger overflow/underflowEVM-Solidity
BendDAO: `isolateRepay()` lack of check `onBehalf == nftOwner`
- Payout
- $0
- Protocol
- BendDAO
- Disclosed
- Sep 3, 2024
- Source
- code4rena
The BendDAO protocol contains an authorization vulnerability in its isolateRepay and isolateRedeem functions that allows users to manipulate the debt accounting of other participants. By failing to verify that the onBehalf parameter matches the owner of the NF …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2024-07-benddao-findings/issues/44
- https://github.com/code-423n4/2024-07-benddao-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.