TwapOracle / registerPair function could register VADER / USDV and USDV / VADER pools. #51
Labels
1 (Low Risk)
Assets are not at risk. State handling, function incorrect as to spec, issues with comments
bug
Something isn't working
sponsor confirmed
Sponsor agrees this is a problem and intends to fix it (OK to use w/ "disagree with severity")
VaderPoolV2
Handle
xYrYuYx
Vulnerability details
Impact
token0 can be VADER or USDV, and there is no check if token1 is VADER or USDV.
So there is possibility to register VADER / USDV pool, and USDV / VADER pool.
Here first one is token0, and second one is token1.
Tools Used
Manually
Recommended Mitigation Steps
Check if token1 is not USDV and VADER
The text was updated successfully, but these errors were encountered: