All reports
highAccess controlEVM-Solidity

Olas: CM can `delegatecall` to any address and bypass all restrictions

Payout
$0
Protocol
Olas
Disclosed
Feb 6, 2024
Source
code4rena

The GuardCM contract in the Olas protocol was intended to restrict the Community Multisig's (CM) actions, but it suffered from an access control flaw due to overly specific filtering. The security guard only enforced restrictions, such as prohibiting delegatec …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.