highAccess controlEVM-Solidity
Palmera: Unauthorized Role Modification Vulnerability in setRole Function
- Payout
- $0
- Protocol
- Palmera
- Disclosed
- Jun 28, 2024
- Source
- hats
Palmera's setRole is designed to bind a user's role to a specific safe through a safeId parameter, but the underlying call only forwards the user address, role, and enabled flag to RolesAuthority.setUserRole, silently ignoring safeId. As a result, roles are wr …
Similar reports
- No close matches yet.
References
- https://github.com/hats-finance/Palmera-0x5fee7541ddcd51ba9f4af606f87b2c42eea655be/issues/70
- https://github.com/hats-finance/Palmera-0x5fee7541ddcd51ba9f4af606f87b2c42eea655be
This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.