mediumAccess controlEVM-Solidity
Palmera: setRole` Function Incorrectly Assigns `_safe.lead` without Validating `enabled` Parameter
- Payout
- $0
- Protocol
- Palmera
- Disclosed
- Jun 24, 2024
- Source
- hats
Palmera's setRole function updates the _safe.lead storage field whenever a lead-related role identifier (SAFE_LEAD or the two SAFE_LEAD variants) is passed, but it ignores the enabled boolean. As a result, a root-safe admin who disables a user's lead role stil …
Similar reports
- No close matches yet.
References
- https://github.com/hats-finance/Palmera-0x5fee7541ddcd51ba9f4af606f87b2c42eea655be/issues/41
- https://github.com/hats-finance/Palmera-0x5fee7541ddcd51ba9f4af606f87b2c42eea655be
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.