get_secret` does not sufficiently validate the caller is a signer
get_secret
can be called by anyone because it does not ensure that the caller signs the transaction
Likelihood:
High: Anyone can call this
Impact:
High: Exposed keys
Modify the get_secret
to check if it's a signer
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.