sechub
HomeServicesAssetsJobsFindingsTicketsGovCheck
Guest Mode. Click here to sign in and access all features

    No separation of Privileged roles

    AGAVE: Deployment Security Audit

    Severity
    Medium
    Status
    Open
    Location(s)

    **Emergency

    SAFE**

    3/4

    Approvals

    required

    to

    execute

    a

    transaction

    Address:

    0x70225281599Ba586039E7BD52736681DFf6c2Fc4

    Owners:

    0x74f72193E880cD5E903CB3cfD2d282fC5F214b28

    EOA

    0x79c815a50F2F0CB91772945d94fC65371f5d9881

    EOA

    0xB5d732D7D494D915BC4EdCd8B64Db756d2C91CFC

    EOA

    0xc44caeb7F0724A156806664d2361fD6f32a2d2C8

    EOA

    **Governance

    SAFE**

    1/2

    Approvals

    required

    to

    execute

    a

    transaction

    Address:

    0xb4c575308221caa398e0dd2cdeb6b2f10d7b000a

    Owners:

    0x70225281599Ba586039E7BD52736681DFf6c2Fc4

    Emergency

    SAFE!!!!

    0x19ed08AF7783959fDDF95642B160E62956718925

    Gnosis

    Zodiac

    Module

    Description

    In LendingPoolAddressesProvider ( 0x3673C22153E363B1da69732c4E0aA71872Bbb87F ) you have 3 important roles:

    • Pool admin: can initialize, update, disable and configure assets/reserves
    • Emergency Admin: has the ability pauses or unpauses all the actions of the protocol, including aToken transfers
    • Owner: is able to set and change the Emergency Admin, Pool admin, PriceOracle among many other highly sensitive configurations

    LendingPoolAddressesProvider together with ATokensAndRatesHelper, StableAndVariableTokensHelper, LendingRateOracle & WETHGateway are all owned by a SAFE, referred in this Finding as the "Governance SAFE", a 1/2 Multisig.

    The following is the current status of the deployed contracts ownership status:

    LendingPoolAddressesProviderRegistry: 0x4baacd04b13523d5e81f398510238e7444e11744

    • Owner: Emergency SAFE

    LendingPoolAddressesProvider: 0x3673c22153e363b1da69732c4e0aa71872bbb87f

    • Owner: Governance SAFE
    • Emergency Admin: Emergency SAFE
    • Pool Admin: Governance SAFE

    StableAndVariableTokensHelper: 0x279b2f090c16e0c34a2e61e153ba5b7eb8d31cc0

    • Owner: Governance SAFE

    ATokensAndRatesHelper: 0x87ccbfb35ba8dbf25445a2fb6d4b69dd3743e2ab

    • Owner: Governance SAFE

    AgaveOracle: 0x64ce22b5ba4175002ac5b6cce3570432ca363c29

    • Owner: Emergency SAFE

    LendingRateOracle: 0xc7313d0a5bf166c984b3e818b59432513d2d4938

    • Owner: Governance SAFE

    WETHGateway: 0x36a644cc38ae257136eeca5919800f364d73fefc

    • Owner: Governance SAFE
    Recommendation

    Ensure there is a clear separation between the Owner role and the Emergency Admin / Pool Admin. Sub7 suggests either:

    1. Assign the Gnosis Zodiac Module directly to the Owner role, ensuring that these highly sensitive changes can only be performed through a governance vote, or,
    2. Assign the Owner role to a completely separate SAFE, with different owners and higher complexity for approvals. Ex. 8/10 approvals required
    Comments
    No comments yet

    No separation of Privileged roles

    AGAVE: Deployment Security Audit

    Severity
    Medium
    Status
    Open