GHSA-x5r5-2qrx-rqj8

    Dashboard / Vulnerabilities / GHSA-x5r5-2qrx-rqj8

    GHSA-x5r5-2qrx-rqj8

    Published: 27 Feb 2024Last Modified: 4 Mar 2024
    Aliases:

    Summary: Transparent TLS may not be applied to Marbles with certain manifest configurations

    Details: Transparent TLS (TTLS) is a MarbleRun feature that wraps plain TCP connections between Marbles in TLS. In the manifest, a user defines the connections that should be considered. ### Impact If a Marble is configured for TTLS, but doesn't have an environment variable defined in its parameters, TTLS is not applied. The traffic will not be encrypted. MarbleRun deployments that don't use TTLS (which is only available with EGo Marbles) are not affected. ### Patches The issue has been patched in [`v1.4.1`](https://github.com/edgelesssys/marblerun/releases/tag/v1.4.1). ### Workarounds Make sure that all Marbles that use TTLS have an environment variable defined in their parameters. ### References For a description of TTLS, see <https://docs.edgeless.systems/marblerun/features/transparent-TLS> See the updated section on TTLS configuration in the manifest: <https://docs.edgeless.systems/marblerun/workflows/define-manifest#tls>

    Affected packages

    Package

    Name: github.com/edgelesssys/marblerun

    Purl: pkg:golang/github.com/edgelesssys/marblerun

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.4.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-x5r5-2qrx-rqj8 | CVE-DB