All reports
highAccess controlEVM-Solidity

Palmera: Unauthorized Role Modification Vulnerability in setRole Function

Payout
$0
Protocol
Palmera
Disclosed
Jun 28, 2024
Source
hats

Palmera's setRole is designed to bind a user's role to a specific safe through a safeId parameter, but the underlying call only forwards the user address, role, and enabled flag to RolesAuthority.setUserRole, silently ignoring safeId. As a result, roles are wr …

Similar reports

  • No close matches yet.

References

This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.