Vulnerability DatabaseGHSA-x5r5-2qrx-rqj8

GHSA-x5r5-2qrx-rqj8
vulnerability analysis and mitigation

Overview

A critical security vulnerability (GHSA-x5r5-2qrx-rqj8) was discovered in MarbleRun versions prior to 1.4.1, affecting the Transparent TLS (TTLS) feature. The vulnerability was disclosed on February 27, 2024. TTLS is designed to wrap plain TCP connections between Marbles in TLS, where connections are defined in the manifest. This vulnerability affects MarbleRun deployments that use TTLS, which is specifically available with EGo Marbles (GitHub Advisory).

Technical details

The vulnerability occurs when a Marble is configured for TTLS but doesn't have an environment variable defined in its parameters. The issue has been assigned a CVSS v3.1 score of 9.1 (Critical), with the following metrics: Attack Vector: Network, Attack Complexity: Low, Privileges Required: None, User Interaction: None, Scope: Unchanged, Confidentiality: High, Integrity: High, Availability: None (GitHub Advisory).

Impact

When exploited, the vulnerability results in TTLS not being applied to the affected Marbles, leaving the traffic unencrypted. This poses a significant security risk as the intended TLS protection for TCP connections between Marbles is not implemented, potentially exposing sensitive communication (GitHub Advisory).

Exploitability

The vulnerability has a low attack complexity and requires no privileges or user interaction to exploit. The network-based attack vector makes it accessible to remote attackers, though there are no public reports of the vulnerability being exploited in the wild (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in MarbleRun version 1.4.1. As a workaround, users should ensure that all Marbles using TTLS have an environment variable defined in their parameters. For deployments that don't use TTLS (only available with EGo Marbles), no action is required (GitHub Release).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management