M-07 MitigationConfirmed #17
Labels
confirmed for report
This issue is confirmed for report
mitigation-confirmed
MR-M-07
satisfactory
satisfies C4 submission criteria; eligible for awards
Lines of code
Vulnerability details
The finding M-07: The traceEnd in BackingManager isn't updating correctly was fully mitigated, and the availability impact on Dutch auctions is no longer present.
As an additional suggestion, possibly with "low" severity, we would like to point out that the new implementation:
does not follow the check-effect-interaction pattern. While we don't believe there is opportunity for a reentrancy exploit (because
tradeEnd
would prevent a dangerous call torebalance
in any case), we would recommend moving thetradeEnd
update before thesuper.settleTrade
call which contains interactions, like done for thedelete tokensOut[sell]
statement.The text was updated successfully, but these errors were encountered: