All reports
mediumLogic errorEVM-Solidity

Inverter Network: LM_PC_KPIRewarder_v1.sol#assertionResolvedCallback() - `LM_PC_KPIRewarder_v1` can be set as a callback address to another assertion in order to set `assertionPending = false`

Payout
$0
Protocol
Inverter Network
Disclosed
Jun 7, 2024
Source
hats

LM_PC_KPIRewarder_v1 implements assertionResolvedCallback to integrate with UMA's OptimisticOracleV3, but the callback never verifies that the passed assertionId was actually created through this contract. Because the id is unchecked, any caller can settle an …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.