Vulnerability GO-2025-3455
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 year ago
February 05, 2025 at 11:27 PM UTC
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast
v0.1.0 - v1.4.0
v0.1.0 - v1.4.0
Summary
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast
Details
Contrast's unauthenticated recovery allows Coordinator impersonation in github.com/edgelesssys/contrast
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
2 months ago
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts in github.com/edgelesssys/contrast
v0.1.0 - v1.20.0 GO-2026-5864
v0.1.0 - v1.20.0 GO-2026-5864
Unknown
2 months ago
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries in github.com/edgelesssys/contrast
v0.1.0 - v1.20.0 GO-2026-5865
v0.1.0 - v1.20.0 GO-2026-5865
Medium Risk
2 months ago
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts
v0.1.0 - v1.20.0 GHSA-3ccm-4qq2-5wrp
v0.1.0 - v1.20.0 GHSA-3ccm-4qq2-5wrp
Low Risk
2 months ago
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries
v0.1.0 - v1.20.0 GHSA-6c87-g9pw-78fx
v0.1.0 - v1.20.0 GHSA-6c87-g9pw-78fx
Unknown
3 months ago
Contras Affected by CopyFile Policy Subversion via Symlinks in github.com/edgelesssys/contrast
v0.1.0 - v1.19.0 GO-2026-5624
v0.1.0 - v1.19.0 GO-2026-5624
Impacted packages
Timeline
Published
1 year ago
February 05, 2025 at 11:27 PM UTC
Last Modified
23 hours ago
September 27, 2026 at 11:55 AM UTC