mediumLogic errorEVM-Solidity
reNFT: `RentPayload`'s signature can be replayed
- Payout
- $0
- Protocol
- reNFT
- Disclosed
- Mar 20, 2024
- Source
- code4rena
reNFT's Create#validateOrder verifies a PayRentPayload signature only against its expiration timestamp and the derived hash of the payload metadata, with no nonce or binding to the specific order being fulfilled. Because OrderMetadata is simple and not unique …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2024-01-renft-findings/issues/162
- https://github.com/code-423n4/2024-01-renft-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.