Skip to main content

WB-E-3 — Attacker calls go-trust /evaluation endpoint directly, bypassing SPOCP firewall

Component: Wallet Backend. Mitigations: SPOCP firewall is fail-closed in production (GIN_MODE=release); /evaluation only evaluates publicly available trust information (TSL membership, OIDF trust anchors) — no user-specific or privileged data is returned. Action: Network-restrict go-trust to application zone as defence-in-depth; no application-layer authentication required given the public nature of the trust information

PropertyValue
SectionElevation of Privilege
Owneroperator

Mapped Controls

ControlTitle
SID-TRUST-02Multi-Registry Trust Framework Support
SID-ACCESS-04SPOCP Policy-Based Query Authorization

Source: STRIDE analysis (April 2026), architecture/stride-threat-model.md