Hello Team,
I identified something which I believe is an opportunity for security improvement.
The operator-cli environment allows other commands to be executed successfully within the shell environment. This should be restricted to allow only required and applicable commands that are specific to Shardeum
I will suggest that any command except the ones listed by Sharduem shouldnot be allowed to execute within the operator cli-environment
CLI part of the operator dashboard
Commands:
status
stake_info
start
stop [options]
stake
unstake [options]
update
version
network-stats
node-settings
set
gui
help [command]
Hello Team,
I identified something which I believe is an opportunity for security improvement.
The operator-cli environment allows other commands to be executed successfully within the shell environment. This should be restricted to allow only required and applicable commands that are specific to Shardeum
I will suggest that any command except the ones listed by Sharduem shouldnot be allowed to execute within the operator cli-environment
CLI part of the operator dashboard
Commands:
status
stake_info
start
stop [options]
stake
unstake [options]
update
version
network-stats
node-settings
set
gui
help [command]