File tree 2 files changed +103
-0
lines changed 2 files changed +103
-0
lines changed Original file line number Diff line number Diff line change
1
+ {
2
+ "schema_version" : " 1.3.1" ,
3
+ "id" : " GO-2024-2583" ,
4
+ "modified" : " 0001-01-01T00:00:00Z" ,
5
+ "published" : " 0001-01-01T00:00:00Z" ,
6
+ "aliases" : [
7
+ " GHSA-x5r5-2qrx-rqj8"
8
+ ],
9
+ "summary" : " Encryption bypass in github.com/edgelesssys/marblerun" ,
10
+ "details" : " Encryption bypass in github.com/edgelesssys/marblerun" ,
11
+ "affected" : [
12
+ {
13
+ "package" : {
14
+ "name" : " github.com/edgelesssys/marblerun" ,
15
+ "ecosystem" : " Go"
16
+ },
17
+ "ranges" : [
18
+ {
19
+ "type" : " SEMVER" ,
20
+ "events" : [
21
+ {
22
+ "introduced" : " 0"
23
+ },
24
+ {
25
+ "fixed" : " 1.4.1"
26
+ }
27
+ ]
28
+ }
29
+ ],
30
+ "ecosystem_specific" : {
31
+ "imports" : [
32
+ {
33
+ "path" : " github.com/edgelesssys/marblerun/marble/premain" ,
34
+ "symbols" : [
35
+ " ActivateRPC" ,
36
+ " GramineActivate" ,
37
+ " PreMain" ,
38
+ " PreMainEgo" ,
39
+ " PreMainEx" ,
40
+ " PreMainMock"
41
+ ]
42
+ },
43
+ {
44
+ "path" : " github.com/edgelesssys/marblerun/coordinator/core" ,
45
+ "symbols" : [
46
+ " Core.Activate" ,
47
+ " Core.setTTLSConfig"
48
+ ]
49
+ }
50
+ ]
51
+ }
52
+ }
53
+ ],
54
+ "references" : [
55
+ {
56
+ "type" : " ADVISORY" ,
57
+ "url" : " https://github.com/edgelesssys/marblerun/security/advisories/GHSA-x5r5-2qrx-rqj8"
58
+ },
59
+ {
60
+ "type" : " FIX" ,
61
+ "url" : " https://github.com/edgelesssys/marblerun/commit/0330ced092253613a07abe7b330ff6ac6fc6e9c6"
62
+ },
63
+ {
64
+ "type" : " FIX" ,
65
+ "url" : " https://github.com/edgelesssys/marblerun/commit/e5bcfe32883d22f3d87ffc9400f9fdb5ecbe3200"
66
+ },
67
+ {
68
+ "type" : " WEB" ,
69
+ "url" : " https://github.com/edgelesssys/marblerun/releases/tag/v1.4.1"
70
+ }
71
+ ],
72
+ "database_specific" : {
73
+ "url" : " https://pkg.go.dev/vuln/GO-2024-2583"
74
+ }
75
+ }
Original file line number Diff line number Diff line change
1
+ id : GO-2024-2583
2
+ modules :
3
+ - module : github.com/edgelesssys/marblerun
4
+ versions :
5
+ - fixed : 1.4.1
6
+ vulnerable_at : 1.4.0
7
+ packages :
8
+ - package : github.com/edgelesssys/marblerun/marble/premain
9
+ symbols :
10
+ - GramineActivate
11
+ - PreMain
12
+ - PreMainEgo
13
+ - PreMainMock
14
+ - PreMainEx
15
+ - ActivateRPC
16
+ - package : github.com/edgelesssys/marblerun/coordinator/core
17
+ symbols :
18
+ - Core.setTTLSConfig
19
+ derived_symbols :
20
+ - Core.Activate
21
+ summary : Encryption bypass in github.com/edgelesssys/marblerun
22
+ ghsas :
23
+ - GHSA-x5r5-2qrx-rqj8
24
+ references :
25
+ - advisory : https://github.com/edgelesssys/marblerun/security/advisories/GHSA-x5r5-2qrx-rqj8
26
+ - fix : https://github.com/edgelesssys/marblerun/commit/0330ced092253613a07abe7b330ff6ac6fc6e9c6
27
+ - fix : https://github.com/edgelesssys/marblerun/commit/e5bcfe32883d22f3d87ffc9400f9fdb5ecbe3200
28
+ - web : https://github.com/edgelesssys/marblerun/releases/tag/v1.4.1
You can’t perform that action at this time.
0 commit comments