Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Bulletin Changes #3120

Merged
merged 22 commits into from
Jul 17, 2024
Merged

Security Bulletin Changes #3120

merged 22 commits into from
Jul 17, 2024

Conversation

karl-cardenas-coding
Copy link
Contributor

@karl-cardenas-coding karl-cardenas-coding commented Jun 18, 2024

Describe the Change

This PR updates the security bulletin index page.

Changed Pages

💻 Preview URL for Page

Jira Tickets

🎫 DOC-1241

Backports

Can this PR be backported?

  • Yes. Remember to add the relevant backport labels to your PR.
  • No. Please leave a short comment below about why this PR cannot be backported.

Copy link

netlify bot commented Jun 18, 2024

Deploy Preview for docs-spectrocloud ready!

Name Link
🔨 Latest commit ebb13f0
🔍 Latest deploy log https://app.netlify.com/sites/docs-spectrocloud/deploys/669800ea853180000871baa4
😎 Deploy Preview https://deploy-preview-3120--docs-spectrocloud.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.

@karl-cardenas-coding karl-cardenas-coding added backport-version-4-0 Backport change to version 4.0 auto-backport Enable backport backport-version-3-4 Backport change to version 3.4 backport-version-4-1 Backport change to version 4.1 backport-version-4-2 Backport change to version 4.2 backport-version-4-3 Backport change to version 4.3 backport-version-4-4 Backport change to version 4.4 labels Jun 18, 2024
@karl-cardenas-coding karl-cardenas-coding changed the title docs: DOC-1241 Security Bulletin Changes Jun 18, 2024
@karl-cardenas-coding karl-cardenas-coding marked this pull request as ready for review July 17, 2024 02:45
@karl-cardenas-coding karl-cardenas-coding requested a review from a team as a code owner July 17, 2024 02:45

| CVE ID | Initial Pub Date | Modified Date | Impacted Product & Version | Vulnerability Type | CVSS Severity | Status |
| ----------------------------------------------- | ---------------- | ------------- | -------------------------- | --------------------------------------- | -------------------------------------------------------- | ------------- |
| [CVE-2023-52425](./cve-2023-52425.md) | 02/04/2024 | 06/14/2024 | Palette 4.4.8 | Third-party component: vSphere-CSI | [7.5](https://nvd.nist.gov/vuln/detail/CVE-2023-52425) | :mag: Ongoing |
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Google.DateFormat] Use 'July 31, 2016' format, not '02/04/2024'.


| CVE ID | Initial Pub Date | Modified Date | Impacted Product & Version | Vulnerability Type | CVSS Severity | Status |
| ----------------------------------------------- | ---------------- | ------------- | -------------------------- | --------------------------------------- | -------------------------------------------------------- | ------------- |
| [CVE-2023-52425](./cve-2023-52425.md) | 02/04/2024 | 06/14/2024 | Palette 4.4.8 | Third-party component: vSphere-CSI | [7.5](https://nvd.nist.gov/vuln/detail/CVE-2023-52425) | :mag: Ongoing |
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Google.DateFormat] Use 'July 31, 2016' format, not '06/14/2024'.


| CVE ID | Last Update | NIST CVE Summary | Our Official Summary | CVE Severity | Status |
| ----------------------------------------------------------------- | ----------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------- | ------------------------------------------------------ | ------- |
| [CVE-2023-52425](https://nvd.nist.gov/vuln/detail/CVE-2023-52425) | 7/16/24 | libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed. | The CVE is reported in vsphere-csi 3.2.0. | [7.5](https://nvd.nist.gov/vuln/detail/CVE-2023-52425) | Ongoing |
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Vale.Spelling] Did you really mean 'libexpat'?


| CVE ID | Last Update | NIST CVE Summary | Our Official Summary | CVE Severity | Status |
| ----------------------------------------------------------------- | ----------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------- | ------------------------------------------------------ | ------- |
| [CVE-2023-52425](https://nvd.nist.gov/vuln/detail/CVE-2023-52425) | 7/16/24 | libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed. | The CVE is reported in vsphere-csi 3.2.0. | [7.5](https://nvd.nist.gov/vuln/detail/CVE-2023-52425) | Ongoing |
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Vale.Spelling] Did you really mean 'reparsings'?


| CVE ID | Last Update | NIST CVE Summary | Our Official Summary | CVE Severity | Status |
| ----------------------------------------------------------------- | ----------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------- | ------------------------------------------------------ | ------- |
| [CVE-2023-52425](https://nvd.nist.gov/vuln/detail/CVE-2023-52425) | 7/16/24 | libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed. | The CVE is reported in vsphere-csi 3.2.0. | [7.5](https://nvd.nist.gov/vuln/detail/CVE-2023-52425) | Ongoing |
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [vale] reported by reviewdog 🐶
[Vale.Terms] Use 'vSphere' instead of 'vsphere'.

@karl-cardenas-coding karl-cardenas-coding merged commit 9bbd508 into master Jul 17, 2024
15 checks passed
@karl-cardenas-coding karl-cardenas-coding deleted the DOC-1241 branch July 17, 2024 18:59
vault-token-factory-spectrocloud bot pushed a commit that referenced this pull request Jul 17, 2024
* docs: DOC-1241

* docs: draft

* chore: updated with link

* docs: updated disclosures

* docs: updated

* chore: updated

* docs: updated

* docs: updates

* chore: updates

* chore: fix

* chore: missing URLs

* chore: updated prettier to exclude cve-page

* chore: added N/A versus leaving blank

* docs: updated CVEs

* docs: update

* docs: added airgap

* docs: fixed minor issue

* docs: fix broken URL

* docs: updated intro langugae

(cherry picked from commit 9bbd508)
@vault-token-factory-spectrocloud
Copy link
Contributor

💔 Some backports could not be created

Status Branch Result
version-4-0 Backport failed because of merge conflicts

You might need to backport the following PRs to version-4-0:
- Create, style, and populate the Tutorials section (#2689)
version-3-4 Backport failed because of merge conflicts

You might need to backport the following PRs to version-3-4:
- chore: DOC-1148 fix missing trailing slash (#2656)
- Refactor/restructure cluster & app profiles sections (#1551)
- docs: refactor for self-hosted Palette DOC-465 (#1597)
- chore: released docs versioning
version-4-1 Backport failed because of merge conflicts

You might need to backport the following PRs to version-4-1:
- Create, style, and populate the Tutorials section (#2689)
version-4-2 Backport failed because of merge conflicts

You might need to backport the following PRs to version-4-2:
- chore: add vale rule (#2106)
version-4-3 Backport failed because of merge conflicts
version-4-4

Note: Successful backport PRs will be merged automatically after passing CI.

Manual backport

To create the backport manually run:

backport --pr 3120

Questions ?

Please refer to the Backport tool documentation and see the Github Action logs for details

vault-token-factory-spectrocloud bot added a commit that referenced this pull request Jul 17, 2024
* docs: DOC-1241

* docs: draft

* chore: updated with link

* docs: updated disclosures

* docs: updated

* chore: updated

* docs: updated

* docs: updates

* chore: updates

* chore: fix

* chore: missing URLs

* chore: updated prettier to exclude cve-page

* chore: added N/A versus leaving blank

* docs: updated CVEs

* docs: update

* docs: added airgap

* docs: fixed minor issue

* docs: fix broken URL

* docs: updated intro langugae

(cherry picked from commit 9bbd508)

Co-authored-by: Karl Cardenas <29551334+karl-cardenas-coding@users.noreply.github.com>
karl-cardenas-coding added a commit that referenced this pull request Jul 17, 2024
* docs: DOC-1241

* docs: draft

* chore: updated with link

* docs: updated disclosures

* docs: updated

* chore: updated

* docs: updated

* docs: updates

* chore: updates

* chore: fix

* chore: missing URLs

* chore: updated prettier to exclude cve-page

* chore: added N/A versus leaving blank

* docs: updated CVEs

* docs: update

* docs: added airgap

* docs: fixed minor issue

* docs: fix broken URL

* docs: updated intro langugae
This was referenced Jul 17, 2024
karl-cardenas-coding added a commit that referenced this pull request Jul 17, 2024
* docs: DOC-1241

* docs: draft

* chore: updated with link

* docs: updated disclosures

* docs: updated

* chore: updated

* docs: updated

* docs: updates

* chore: updates

* chore: fix

* chore: missing URLs

* chore: updated prettier to exclude cve-page

* chore: added N/A versus leaving blank

* docs: updated CVEs

* docs: update

* docs: added airgap

* docs: fixed minor issue

* docs: fix broken URL

* docs: updated intro langugae
karl-cardenas-coding added a commit that referenced this pull request Jul 17, 2024
* docs: DOC-1241

* docs: draft

* chore: updated with link

* docs: updated disclosures

* docs: updated

* chore: updated

* docs: updated

* docs: updates

* chore: updates

* chore: fix

* chore: missing URLs

* chore: updated prettier to exclude cve-page

* chore: added N/A versus leaving blank

* docs: updated CVEs

* docs: update

* docs: added airgap

* docs: fixed minor issue

* docs: fix broken URL

* docs: updated intro langugae
karl-cardenas-coding added a commit that referenced this pull request Jul 17, 2024
* docs: DOC-1241

* docs: draft

* chore: updated with link

* docs: updated disclosures

* docs: updated

* chore: updated

* docs: updated

* docs: updates

* chore: updates

* chore: fix

* chore: missing URLs

* chore: updated prettier to exclude cve-page

* chore: added N/A versus leaving blank

* docs: updated CVEs

* docs: update

* docs: added airgap

* docs: fixed minor issue

* docs: fix broken URL

* docs: updated intro langugae
karl-cardenas-coding added a commit that referenced this pull request Jul 17, 2024
* docs: DOC-1241

* docs: draft

* chore: updated with link

* docs: updated disclosures

* docs: updated

* chore: updated

* docs: updated

* docs: updates

* chore: updates

* chore: fix

* chore: missing URLs

* chore: updated prettier to exclude cve-page

* chore: added N/A versus leaving blank

* docs: updated CVEs

* docs: update

* docs: added airgap

* docs: fixed minor issue

* docs: fix broken URL

* docs: updated intro langugae
karl-cardenas-coding added a commit that referenced this pull request Jul 17, 2024
* docs: DOC-1241

* docs: draft

* chore: updated with link

* docs: updated disclosures

* docs: updated

* chore: updated

* docs: updated

* docs: updates

* chore: updates

* chore: fix

* chore: missing URLs

* chore: updated prettier to exclude cve-page

* chore: added N/A versus leaving blank

* docs: updated CVEs

* docs: update

* docs: added airgap

* docs: fixed minor issue

* docs: fix broken URL

* docs: updated intro langugae
karl-cardenas-coding added a commit that referenced this pull request Jul 17, 2024
* docs: DOC-1241

* docs: draft

* chore: updated with link

* docs: updated disclosures

* docs: updated

* chore: updated

* docs: updated

* docs: updates

* chore: updates

* chore: fix

* chore: missing URLs

* chore: updated prettier to exclude cve-page

* chore: added N/A versus leaving blank

* docs: updated CVEs

* docs: update

* docs: added airgap

* docs: fixed minor issue

* docs: fix broken URL

* docs: updated intro langugae
karl-cardenas-coding added a commit that referenced this pull request Jul 17, 2024
* docs: DOC-1241

* docs: draft

* chore: updated with link

* docs: updated disclosures

* docs: updated

* chore: updated

* docs: updated

* docs: updates

* chore: updates

* chore: fix

* chore: missing URLs

* chore: updated prettier to exclude cve-page

* chore: added N/A versus leaving blank

* docs: updated CVEs

* docs: update

* docs: added airgap

* docs: fixed minor issue

* docs: fix broken URL

* docs: updated intro langugae
karl-cardenas-coding added a commit that referenced this pull request Jul 17, 2024
* docs: DOC-1241

* docs: draft

* chore: updated with link

* docs: updated disclosures

* docs: updated

* chore: updated

* docs: updated

* docs: updates

* chore: updates

* chore: fix

* chore: missing URLs

* chore: updated prettier to exclude cve-page

* chore: added N/A versus leaving blank

* docs: updated CVEs

* docs: update

* docs: added airgap

* docs: fixed minor issue

* docs: fix broken URL

* docs: updated intro langugae
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
auto-backport Enable backport backport-version-3-4 Backport change to version 3.4 backport-version-4-0 Backport change to version 4.0 backport-version-4-1 Backport change to version 4.1 backport-version-4-2 Backport change to version 4.2 backport-version-4-3 Backport change to version 4.3 backport-version-4-4 Backport change to version 4.4
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant