You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Finding from security assessment 23.12 (2023-11-21)
Likelihood for human error in accidentally assigning a role with much higher rights (view_wallets, update_wallets) is high, when the roles are only differentiated by a single letter s.
Some measure to avoid accidentally assigning the *_wallets to a user should be implemented, e.g., by renaming either the _wallet variant or the _wallets variant. Other counter-measure
The text was updated successfully, but these errors were encountered:
@pablosec This issue is somewhat misplaced, as we don't control the assignment of roles. This should be coordinated with portal first. We can accommodate such a change after it has been deployed to portal.
Finding from security assessment 23.12 (2023-11-21)
view_wallets
,update_wallets
) is high, when the roles are only differentiated by a single letters
.*_wallets
to a user should be implemented, e.g., by renaming either the_wallet
variant or the_wallets
variant. Other counter-measureThe text was updated successfully, but these errors were encountered: