getCommitHash is an unreliable proof that _prevPollID exists
See original GitHub issueIn commitVote
, we check to ensure that the insert position (_prevPollID
) actually exists by checking getCommitHash(msg.sender, _prevPollID) != 0
. If a user sets their commit hash for that poll to zero, that check will fail even though it is a valid insertion position.
Recommendation
Use DLL.contains
to verify that _prevPollID
is a valid insertion position.
Issue Analytics
- State:
- Created 6 years ago
- Comments:5 (3 by maintainers)
Top Results From Across the Web
TCR Audit Report by ConsenSys Diligence - GitHub
3.2 - getCommitHash is an unreliable proof that _prevPollID exists. Severity: Major. In commitVote , we check to ensure that the insert position ......
Read more >Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start FreeTop Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found
Top GitHub Comments
i love you
https://github.com/ConsenSys/PLCRVoting/commit/1fec53b876156d8f219d09c5bc871e83c14b4fee