Stale data from oracle #22
Labels
2 (Med Risk)
Assets not at direct risk, but function/availability of the protocol could be impacted or leak value
bug
Something isn't working
duplicate-655
satisfactory
satisfies C4 submission criteria; eligible for awards
Lines of code
https://github.com/code-423n4/2022-12-tigris/blob/496e1974ee3838be8759e7b4096dbee1b8795593/contracts/utils/TradingLibrary.sol#L113
Vulnerability details
Impact
Chainlink
latestAnswer()
is deprecated. It might return stale data or incomplete round answer.Proof of Concept
https://github.com/code-423n4/2022-12-tigris/blob/496e1974ee3838be8759e7b4096dbee1b8795593/contracts/utils/TradingLibrary.sol#L113
Recommended Mitigation Steps
Check for stale price and round completeness using
latestRoundData()
The text was updated successfully, but these errors were encountered: