unlockShares
wrong comment
#135
Labels
1 (Low Risk)
Assets are not at risk. State handling, function incorrect as to spec, issues with comments
bug
Something isn't working
sponsor confirmed
Sponsor agrees this is a problem and intends to fix it (OK to use w/ "disagree with severity")
Handle
cmichel
Vulnerability details
The strategy contracts define an
unlockShares
function that must accept anasset
parameter as the share token (yield token, aToken, cToken, etc.), otherwise, the code does not work.However, all comments say that
asset
is the address of the underlying token.Recommended Mitigation Steps
Fix the comments for all
unlockShares
by sayingasset
is the share token, not the underlying token.The text was updated successfully, but these errors were encountered: