Skip to content

Latest commit

 

History

History
19 lines (12 loc) · 902 Bytes

2024-01-26.md

File metadata and controls

19 lines (12 loc) · 902 Bytes

Jan-26-2024 - Vulnerability in Deployment Rights Assignment for Decentraland Names

Reported on Immunefi Jan-26-2024
Mitigation Jan-26-2024
Solution Completed Jan-26-2024

Description

Access to deployment on virtual worlds is achievable without requiring the signature of the name's owner. Deployment permissions for any Decentral and (DCI) world can be obtained independently, without requiring any direct engagement from the name's proprietor. The content server responsible for managing authorized addresses does not verify the signature of the received AuthChain. As a result, deployment permissions can be granted without the explicit consent or authorization of the name's owner.

Severity

Websites & Applications - Low.

Solution

Fix permissions checks