VDB
Sign up
HIGH

GHSA-j3rq-4xjw-xg63

Go package github.com/edgelesssys/marblerun CLI commands susceptible to MITM attacks

Quick fix

GHSA-j3rq-4xjw-xg63 — github.com/edgelesssys/marblerun: upgrade to the fixed version with the command below.

go get github.com/edgelesssys/marblerun@v1.4.0

Details

### Impact Any CLI command issued to a Coordinator after the Manifest has been set, is susceptible to be redirected to another MarbleRun Coordinator instance, which runs the same binary, but potentially a different manifest.

### Patches The issue has been patched in [`v1.4.0`](https://github.com/edgelesssys/marblerun/releases/tag/v1.4.0)

### Workarounds

Directly using the REST API of the Coordinator and manually verifying and pinning the certificate to a set Manifest avoids the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/edgelesssys/marblerun
Introduced in: 0Fixed in: 1.4.0
Fixgo get github.com/edgelesssys/marblerun@v1.4.0

References