HIGH
GHSA-6w5f-5wgr-qjg5
Constellation allows Emergency shell access during initramfs boot phase
Quick fix
GHSA-6w5f-5wgr-qjg5 — github.com/edgelesssys/constellation/v2: upgrade to the fixed version with the command below.
go get github.com/edgelesssys/constellation/v2@v2.6.0Details
### Impact
An active attacker could let the boot fail on purpose in the initramfs, dropping the serial console into an emergency shell. This gives attackers with access to the serial console full control over the VM.
### Patches
The issue has been patched in [v2.6.0](https://github.com/edgelesssys/constellation/releases/tag/v2.6.0).
### Workarounds
none
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/edgelesssys/constellation/v2
Introduced in:
0Fixed in: 2.6.0Fix
go get github.com/edgelesssys/constellation/v2@v2.6.0