Skip to content

Commit

Permalink
turvy_fuzz data for issue #389
Browse files Browse the repository at this point in the history
  • Loading branch information
code423n4 committed Jun 9, 2023
1 parent ffd67b8 commit 213ae4a
Showing 1 changed file with 10 additions and 0 deletions.
10 changes: 10 additions & 0 deletions data/turvy_fuzz-Q.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
### Manager can disable erInspectionMode when it's Cooldown is not completed
## Summary
use of wrong operator

## Vulnerability Details
https://github.com/code-423n4/2023-06-stader/blob/main/contracts/StaderOracle.sol#L187
Due to the use of the wrong operator (&& instead of ||), manager can still disable `erInspection Mode` even when it's Cooldown is not completed. Also when not in cooldown, absolutely anyone can still disable it due to the && operator

## Recommendation:
use || instead of &&.

0 comments on commit 213ae4a

Please sign in to comment.