Skip to content

CLI commands susceptible to MITM attacks

High
daniel-weisse published GHSA-j3rq-4xjw-xg63 Dec 4, 2023

Package

marblerun (CLI)

Affected versions

< v1.4.0

Patched versions

v1.4.0

Description

Impact

Any CLI command issued to a Coordinator after the Manifest has been set, is susceptible to be redirected to another MarbleRun Coordinator instance, which runs the same binary, but potentially a different manifest.

Patches

The issue has been patched in v1.4.0

Workarounds

Directly using the REST API of the Coordinator and manually verifying and pinning the certificate to a set Manifest avoids the issue.

Severity

High

CVE ID

No known CVE

Weaknesses

No CWEs