highAccess controlEVM-Solidity
Palmera: Unauthorized Access Control Due to Retained Root Role When Root Safe Exits and Joins New Org
- Payout
- $0
- Protocol
- Palmera
- Disclosed
- Jun 30, 2024
- Source
- hats
Palmera's module that manages Safe-based organizations grants the ROOT_SAFE role when a safe creates an organization, but the addSafe path that re-ingests an existing safe into a new organization never revokes a pre-existing ROOT_SAFE grant. Because roles are …
Similar reports
- No close matches yet.
References
- https://github.com/hats-finance/Palmera-0x5fee7541ddcd51ba9f4af606f87b2c42eea655be/issues/76
- https://github.com/hats-finance/Palmera-0x5fee7541ddcd51ba9f4af606f87b2c42eea655be
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.