Project

One World
NFTDeFi
15,000 USDC
View results
Submission Details
Severity: medium
Invalid

defaultAdmin can not revoke minter's role in OWPIdentity

Vulnerability Details

while openzeppelin AccessControl.sol provides the ability for minter role to be revoked or renounced, the functions are not exposed or overidden in OWPIdentity.sol.

Impact

A mischevious minter can mint and burn token with the inability of being able to be removed. If the role is overtaken by hackers it cant also be changed by the default admin

Tools Used

manual review

Recommendations

expose the roles that the defaultAdmin should be able to access

Updates

Lead Judging Commences

0xbrivan2 Lead Judge 10 months ago
Submission Judgement Published
Invalidated
Reason: Incorrect statement
0xbrivan2 Lead Judge 10 months ago
Submission Judgement Published
Invalidated
Reason: Incorrect statement

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.