Past defeated proposal may get executed when proposal to update to lower quorum votes is passed. #673
Labels
3 (High Risk)
Assets can be stolen/lost/compromised directly
bug
Something isn't working
insufficient quality report
This report is not of sufficient quality
unsatisfactory
does not satisfy C4 submission criteria; not eligible for awards
Lines of code
https://github.com/code-423n4/2023-12-ethereumcreditguild/blob/2376d9af792584e3d15ec9c32578daa33bb56b43/src/governance/GuildGovernor.sol#L98-L103
Vulnerability details
Impact
When a proposal to lower quorum votes is passed. Past proposals may become executable if they had been defeated only due to lack of quorum votes and the number of votes it received past new quorum requirement.
Vulnerability details
Where :- In Governance.sol
Proof of Concept
GHSA-xrc4-737v-9q75
Tools Used
Manual review
Recommended Mitigation Steps
Assessed type
Governance
The text was updated successfully, but these errors were encountered: