blob: e97390ef51d4d3f118691a4a4d7f46d3329236c5 [file] [log] [blame]
id: GO-2025-3450
modules:
- module: github.com/edgelesssys/marblerun
versions:
- fixed: 1.7.0
vulnerable_at: 1.6.0
summary: MarbleRun unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/marblerun
ghsas:
- GHSA-w7wm-2425-7p2h
references:
- advisory: https://github.com/edgelesssys/marblerun/security/advisories/GHSA-w7wm-2425-7p2h
- fix: https://github.com/edgelesssys/marblerun/commit/e4864f9f1d0f12a4a7d28514da43bcc75603a5b5
- web: https://github.com/edgelesssys/marblerun/releases/tag/v1.7.0
source:
id: GHSA-w7wm-2425-7p2h
created: 2025-02-05T18:05:04.017988-05:00
review_status: UNREVIEWED