internal/handlers/app.go — parsePortValues() only checks range 1-65535
Impact
Privileged port binding: Users can bind to ports 1-1023 (e.g., port 80, 443, 22) potentially hijacking host services
Service exposure: All ports bound to all interfaces — no way to restrict to localhost or internal networks
Port conflicts: Two apps can try to bind the same port, causing deployment failure with an unclear error. The DB has UNIQUE(host_port, protocol) but only within a single app
Port 8080 hijack: A user could bind to port 8080 and intercept upaas's own traffic (depending on network setup)
Suggested Fix
Add configurable minimum port (e.g., UPAAS_MIN_HOST_PORT=1024) to block privileged ports
Add configurable bind IP (e.g., UPAAS_BIND_IP=127.0.0.1)
Add cross-app port conflict detection before creating container
Block upaas's own port from being mapped
Severity
CRITICAL — Privileged port hijacking can intercept host services including upaas itself.
## Summary
Port mappings hardcode `HostIP: "0.0.0.0"` (all interfaces) and allow any port 1-65535 including privileged ports. No conflict detection between apps.
## Location
- `internal/docker/client.go` — `buildPortConfig()` hardcodes `HostIP: "0.0.0.0"`
- `internal/handlers/app.go` — `parsePortValues()` only checks range 1-65535
## Impact
1. **Privileged port binding**: Users can bind to ports 1-1023 (e.g., port 80, 443, 22) potentially hijacking host services
2. **Service exposure**: All ports bound to all interfaces — no way to restrict to localhost or internal networks
3. **Port conflicts**: Two apps can try to bind the same port, causing deployment failure with an unclear error. The DB has `UNIQUE(host_port, protocol)` but only within a single app
4. **Port 8080 hijack**: A user could bind to port 8080 and intercept upaas's own traffic (depending on network setup)
## Suggested Fix
1. Add configurable minimum port (e.g., `UPAAS_MIN_HOST_PORT=1024`) to block privileged ports
2. Add configurable bind IP (e.g., `UPAAS_BIND_IP=127.0.0.1`)
3. Add cross-app port conflict detection before creating container
4. Block upaas's own port from being mapped
## Severity
**CRITICAL** — Privileged port hijacking can intercept host services including upaas itself.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
Port mappings hardcode
HostIP: "0.0.0.0"(all interfaces) and allow any port 1-65535 including privileged ports. No conflict detection between apps.Location
internal/docker/client.go—buildPortConfig()hardcodesHostIP: "0.0.0.0"internal/handlers/app.go—parsePortValues()only checks range 1-65535Impact
UNIQUE(host_port, protocol)but only within a single appSuggested Fix
UPAAS_MIN_HOST_PORT=1024) to block privileged portsUPAAS_BIND_IP=127.0.0.1)Severity
CRITICAL — Privileged port hijacking can intercept host services including upaas itself.
WONTFIX