29137 - [SC - High] ZeroLend token is not behaving properly while c...

Submitted on Mar 8th 2024 at 09:38:30 UTC by @dontonka for Boost | ZeroLend

Report ID: #29137

Report type: Smart Contract

Report severity: High

Target: https://github.com/zerolend/governance

Impacts:

  • ZeroLendToken not properly behaving in prelaunch phase

Description

Brief/Intro

ZeroLendToken should allow to operate with Whitelisted users even if contract is paused, which is not the case in the current implementation which seems to warrant Low severity.

Vulnerability Details

The current condition is inaccurate.

Impact Details

Whitelisted user will not be able to use the contract while the contract is paused.

Recommendation

Apply the following changes.

Proof of Concept

Run the following command to create the fresh testing environnement based on Foundry.

Apply the recommended fix and test will pass as follow.

ZeroLendToken.sol, the original file.

ZeroLendToken.t.sol

Last updated

Was this helpful?