Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Block remote code execution #225

Open
bweengener opened this issue Jul 18, 2022 · 1 comment
Open

Block remote code execution #225

bweengener opened this issue Jul 18, 2022 · 1 comment
Labels
bug Something isn't working question Further information is requested user-story

Comments

@bweengener
Copy link
Contributor

bweengener commented Jul 18, 2022

User Story:
As a host, I don’t want users to be able to arbitrarily execute code on my server to ensure the integrity of the polls and ensure user’s can’t hack me/ cheat.

@L17L L17L added the bug Something isn't working label May 7, 2024
@florian-str florian-str changed the title As a host I don’t want users to be able to arbitrarily execute code on my server to ensure the integrity of the polls and ensure user’s can’t hack me/ cheat. Block remote code execution May 21, 2024
@florian-str florian-str added the question Further information is requested label May 21, 2024
@florian-str
Copy link
Contributor

An old issue (#124) describes the problem in more detail:

With access to perform: and similar messages, one could wreak havoc and circumvent any security measurements put in place. We should guard against this, possibly by only allowing messages to be sent that are implemented directly on the object that's messaged (and not inherited handlers).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working question Further information is requested user-story
Projects
None yet
Development

No branches or pull requests

3 participants