-
Notifications
You must be signed in to change notification settings - Fork 171
Open
Labels
enhancementNew feature or requestNew feature or requesthelmImprovements regarding the helm chartImprovements regarding the helm chart
Description
Currently a user could use RCE or SSRF vulnerabilities to connect to JuiceShop instances of other users.
This would kind of be a awesome challenge in itself 😅
Like: "Steal the challenge progress from another team"
But as we (currently 😉) don't have the possibility to add new Challenges at run time it would probably be best to prohibit any traffic coming from JuiceShop to other JuiceShop pods via k8s NetworkPolicies. Might even work to prevent any cluster internal traffic from the JuiceShop this would have to be tested to ensure that this doesn't cause troubles with the juice-balancer.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or requesthelmImprovements regarding the helm chartImprovements regarding the helm chart