mediumLogic errorCosmos-SDK
Allora: The malicious node may not execute the http request
- Payout
- $0
- Protocol
- Allora
- Disclosed
- Jul 19, 2024
- Source
- sherlock
The Allora chain's topics handler issues an outbound HTTP POST to a blockless API from inside the PrepareProposalHandler, using a Go http client targeting the BLOCKLESS_API_URL variable. Because this side-effecting call runs in the block production path and it …
Similar reports
- No close matches yet.
References
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.