The README states that "In order for someone to be considered NICE or EXTRA_NICE they must be first 'checked twice' by Santa."
The checkList() function accepts Status.NICE or Status.EXTRA_NICE as valid parameters, allowing these statuses to be set on the first check.
Likelihood:
Santa (or any attacker if H-01 is not fixed) can set NICE/EXTRA_NICE status on first check
Impact:
Users can be marked as NICE or EXTRA_NICE without the required "checked twice" verification
Bypasses the double-check security mechanism
Users may collect presents after only one check
The contest is live. Earn rewards by submitting a finding.
Submissions are being reviewed by our AI judge. Results will be available in a few minutes.
View all submissionsThe contest is complete and the rewards are being distributed.