HIGH
GHSA-j3rq-4xjw-xg63
Go package github.com/edgelesssys/marblerun CLI commands susceptible to MITM attacks
Quick fix
GHSA-j3rq-4xjw-xg63 — github.com/edgelesssys/marblerun: upgrade to the fixed version with the command below.
go get github.com/edgelesssys/marblerun@v1.4.0Details
### Impact Any CLI command issued to a Coordinator after the Manifest has been set, is susceptible to be redirected to another MarbleRun Coordinator instance, which runs the same binary, but potentially a different manifest.
### Patches The issue has been patched in [`v1.4.0`](https://github.com/edgelesssys/marblerun/releases/tag/v1.4.0)
### Workarounds
Directly using the REST API of the Coordinator and manually verifying and pinning the certificate to a set Manifest avoids the issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/edgelesssys/marblerun
Introduced in:
0Fixed in: 1.4.0Fix
go get github.com/edgelesssys/marblerun@v1.4.0