Skip to content

Commit 64e2b8c

Browse files
authored
Merge pull request #1296 from input-output-hk/jpraynaud/mithril-relay-security-advisory-dev-blog
Mithril relay security advisory dev blog post
2 parents 5d3de6d + 5d38cb9 commit 64e2b8c

File tree

1 file changed

+23
-0
lines changed

1 file changed

+23
-0
lines changed
Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
---
2+
title: Mithril Protocol’s Mainnet Beta Launch
3+
authors:
4+
- name: Mithril Team
5+
tags: [spo, mithril signer, mithril relay, mainnet, production, beta, security]
6+
---
7+
8+
### Mithril relay could expose Cardano block producer internal IP when updated (Security Advisory)
9+
10+
The Mithril team has published a [security advisory](https://github.com/input-output-hk/mithril/security/advisories/GHSA-9m3h-72xj-x2gq) to destination of SPOs running a Mithril signer/relay on the `mainnet` infrastructure:
11+
12+
- **Identifier**: GHSA-9m3h-72xj-x2gq
13+
- **Title**: Mithril relay could expose Cardano block producer internal IP when updated
14+
- **Location**: https://github.com/input-output-hk/mithril/security/advisories/GHSA-9m3h-72xj-x2gq
15+
- **Severity**: High (7.2/10)
16+
17+
:::danger
18+
19+
We strongly encourage all the `mainnet` SPOs to update the listening port of their **Mithril relay** in order to prevent the issue, with the process explained in the **Workarounds** section of the [security advisory](https://github.com/input-output-hk/mithril/security/advisories/GHSA-9m3h-72xj-x2gq).
20+
21+
:::
22+
23+
Feel free to reach out to us on the [Discord channel](https://discord.gg/5kaErDKDRq) for questions and/or help.

0 commit comments

Comments
 (0)