All reports
mediumAccess controlEVM-Solidity

Palmera: setRole` Function Incorrectly Assigns `_safe.lead` without Validating `enabled` Parameter

Payout
$0
Protocol
Palmera
Disclosed
Jun 24, 2024
Source
hats

Palmera's setRole function updates the _safe.lead storage field whenever a lead-related role identifier (SAFE_LEAD or the two SAFE_LEAD variants) is passed, but it ignores the enabled boolean. As a result, a root-safe admin who disables a user's lead role stil …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.