Skip to content

Malicious dependency injection #1046

@ale-linux

Description

@ale-linux

A malicious view can override the services offered by the supplied view.Context (e.g. the signer service, the fabric network service..) to override their behaviour. Owing to the fact that the view context is not isolated across view executions, any malicious modification performed by a view can impact all other views.

The attack is prototyped here.

Metadata

Metadata

Labels

View APIRelated to FSC ViewsbugSomething isn't workingcomm

Type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions