Trail of Bits

wasmCloud

Type

Security review

Client

The Open Source Technology Foundation

Date

2023-09

Domain

AppSec

Effort

6 wks

Section

Technology Product Reviews

Trail of Bits's security review of The Open Source Technology Foundation (Sep 2023) identified 5 issues: 2 low, 2 informational, and 1 undetermined.

Findings · 5

  1. 1 Out-of-bounds crash in extract_claims Low
  2. 2 Stack overflow while enumerating containers in blobstore-fs Low
  3. 3 Denial of service in blobstore-s3 using malicious actor Undetermined
  4. 4 Unexpected panic in validate_token Informational
  5. 5 Incorrect error message when starting actor from file Informational

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related