highAccess controlEVM-Solidity
Palmera: isSafeLead` Function Lacks Role Authorization Check, Leading to Unauthorized Access
- Payout
- $0
- Protocol
- Palmera
- Disclosed
- Jun 24, 2024
- Source
- hats
Palmera's isSafeLead view reports whether a user is the lead for a safe by comparing against a stored _safe.lead attribute on the Safe struct, whereas lead privileges are actually granted and revoked through the separate RolesAuthority contract. When disableSa …
Similar reports
- No close matches yet.
References
- https://github.com/hats-finance/Palmera-0x5fee7541ddcd51ba9f4af606f87b2c42eea655be/issues/38
- https://github.com/hats-finance/Palmera-0x5fee7541ddcd51ba9f4af606f87b2c42eea655be
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.