Skip to content

Missing whistleblower index check #1910

@paulhauner

Description

@paulhauner

Description

We fail to ensure that the whistleblower_index is in bounds:

increase_balance(
state,
whistleblower_index,
whistleblower_reward.safe_sub(proposer_reward)?,
)?;

This is not exploitable in this version of the spec, however we should still fix it.

Metadata

Metadata

Assignees

Labels

A0bugSomething isn't working

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions