All reports
highLogic errorEVM-Solidity

Palmera: Ineffective Revocation of Multiple Roles in `disableSafeLeadRoles` Function

Payout
$0
Protocol
Palmera
Disclosed
Jun 24, 2024
Source
hats

Palmera's disableSafeLeadRoles privilege-revocation path is implemented as a chain of if/else-if branches, so once any one Safe Lead role matches and is revoked the remaining branches are skipped. A Lead who holds more than one Safe Lead role (for example both …

Similar reports

  • No close matches yet.

References

This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.