Skip to main content

WB-E-2 — Network-reachable admin port grants full tenant/user CRUD

Component: Wallet Backend. Mitigations: Admin API token authentication + operator-enforced network exposure controls (ClusterIP/Ingress scope + NetworkPolicy). Action: Document and validate Kubernetes policy baseline for port 8081 in deployment guides.

PropertyValue
SectionElevation of Privilege
Owneroperator

Mapped Controls

ControlTitle
SID-HARD-03Network Segmentation (Separate Server Ports)

Source: STRIDE analysis (April 2026), architecture/stride-threat-model.md