highAccess controlEVM-Solidity
Perennial V2 Update #3: Lack of access control in the `MarketFactory.updateExtension()` function.
- Payout
- $0
- Protocol
- Perennial V2 Update #3
- Disclosed
- Sep 13, 2024
- Source
- sherlock
Perennial's 2.3 authorization update introduced protocol-wide "extension" operators via `MarketFactory.updateExtension()`, but the function shipped without an `onlyOwner` modifier. Any caller can register any address as an extension, and since extensions are t …
Similar reports
- No close matches yet.
References
This report is already public and closed. CoinBuggie never publishes active or unpatched vulnerability data.