Private vault owners cannot withdraw #403
Labels
3 (High Risk)
Assets can be stolen/lost/compromised directly
bug
Something isn't working
duplicate-489
satisfactory
satisfies C4 submission criteria; eligible for awards
Lines of code
https://github.com/code-423n4/2023-01-astaria/blob/main/src/Vault.sol#L72
Vulnerability details
Impact
SafeTransferFrom requires approval, so it's not possible for the vault owner to withdraw from his private vault.
Proof of Concept
Tools Used
VSCode, Foundry
Recommended Mitigation Steps
Use safeTransfer instead.
The text was updated successfully, but these errors were encountered: