Skip to content

Commit

Permalink
docs: 10-14-24 cve updates (#4280) (#4291)
Browse files Browse the repository at this point in the history
* 10-14-24 cve updates

* ci: auto-formatting prettier issues

* chore: fix redirect

---------

Co-authored-by: frederickjoi <[email protected]>
Co-authored-by: Karl Cardenas <[email protected]>
(cherry picked from commit 36ebec5)

Co-authored-by: frederickjoi <[email protected]>
  • Loading branch information
1 parent be1216c commit da67d29
Show file tree
Hide file tree
Showing 107 changed files with 1,749 additions and 322 deletions.
9 changes: 6 additions & 3 deletions docs/docs-content/security-bulletins/reports/cve-2005-2541.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,10 +35,13 @@ Ongoing

## Affected Products & Versions

- Palette VerteX 4.4.14
- Palette VerteX airgap 4.4.14
- Palette VerteX 4.5.3
- Palette Enterprise 4.5.3

## Revision History

- 1.0 08/16/2024 Initial Publication
- 2.0 08/17/2024 Added Palette VerteX 4.4.14 to Affected Products
- 3.0 09/25/2024 CVE remediated in Palette VerteX 4.4.18
- 2.0 08/17/2024 Added Palette VerteX airgap 4.4.14 to Affected Products
- 3.0 09/25/2024 CVE remediated in Palette VerteX airgap 4.4.18
- 4.0 10/14/2024 Added Palette Enterprise & Palette VerteX 4.5.3 to Affected Products
43 changes: 43 additions & 0 deletions docs/docs-content/security-bulletins/reports/cve-2011-4116.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
---
sidebar_label: "CVE-2011-4116"
title: "CVE-2011-4116"
description: "Lifecycle of CVE-2011-4116"
hide_table_of_contents: true
sidebar_class_name: "hide-from-sidebar"
toc_max_heading_level: 2
tags: ["security", "cve"]
---

## CVE Details

[CVE-2011-4116](https://nvd.nist.gov/vuln/detail/CVE-2011-4116)

## Last Update

10/14/24

## NIST CVE Summary

\_is_safe in the File::Temp module for Perl does not properly handle symlinks.

## Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

## CVE Severity

[7.5](https://nvd.nist.gov/vuln/detail/CVE-2011-4116)

## Status

Ongoing

## Affected Products & Versions

- Palette Enterprise 4.5.3
- Palette VerteX 4.5.3

## Revision History

- 1.0 10/14/24 Initial Publication
- 2.0 10/14/2024 Added Palette Enterprise & Palette VerteX 4.5.3 to Affected Products
13 changes: 8 additions & 5 deletions docs/docs-content/security-bulletins/reports/cve-2012-2663.md
Original file line number Diff line number Diff line change
Expand Up @@ -37,12 +37,15 @@ Ongoing

## Affected Products & Versions

- Palette VerteX 4.4.14, 4.4.18, 4.5.3
- Palette Enterprise 4.4.18, 4.5.3
- Palette VerteX airgap 4.4.14, 4.4.18, 4.5.3
- Palette Enterprise airgap 4.4.18, 4.5.3
- Palette VerteX 4.5.3
- Palette Enterprise 4.5.3

## Revision History

- 1.0 08/16/2024 Initial Publication
- 2.0 08/17/2024 Added Palette VerteX 4.4.14 to Affected Products
- 3.0 09/17/2024 Added Palette VerteX 4.4.18 & Palette Enterprise 4.4.18 to Affected Products
- 4.0 10/10/2024 Added Palette VerteX 4.5.3 & Palette Enterprise 4.5.3 to Affected Products
- 2.0 08/17/2024 Added Palette VerteX airgap 4.4.14 to Affected Products
- 3.0 09/17/2024 Added Palette VerteX airgap 4.4.18 & Palette Enterprise airgap 4.4.18 to Affected Products
- 4.0 10/10/2024 Added Palette VerteX airgap 4.5.3 & Palette Enterprise airgap 4.5.3 to Affected Products
- 5.0 10/14/2024 Added Palette Enterprise & Palette VerteX 4.5.3 to Affected Products
Original file line number Diff line number Diff line change
Expand Up @@ -37,10 +37,10 @@ Ongoing

## Affected Products & Versions

- Palette VerteX 4.4.14
- Palette VerteX airgap 4.4.14

## Revision History

- 1.0 08/16/2024 Initial Publication
- 2.0 08/17/2024 Added palette VerteX 4.4.14 to Affected Products
- 3.0 09/25/2024 CVE remediated in Palette VerteX 4.4.18
- 2.0 08/17/2024 Added Palette VerteX airgap 4.4.14 to Affected Products
- 3.0 09/25/2024 CVE remediated in Palette VerteX airgap 4.4.18
5 changes: 3 additions & 2 deletions docs/docs-content/security-bulletins/reports/cve-2015-8855.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,9 +36,10 @@ Ongoing

## Affected Products & Versions

- Palette VerteX 4.4.11
- Palette VerteX airgap 4.4.11

## Revision History

- 1.0 07/31/2024 Initial Publication
- 2.0 08/17/2024 Remediated in Palette VerteX 4.4.14 -- 3.0 09/25/2024 Remediated in Palette VerteX 4.4.18
- 2.0 08/17/2024 Remediated in Palette VerteX airgap 4.4.14
- 3.0 09/25/2024 Remediated in Palette VerteX airgap 4.4.18
6 changes: 3 additions & 3 deletions docs/docs-content/security-bulletins/reports/cve-2016-1585.md
Original file line number Diff line number Diff line change
Expand Up @@ -34,10 +34,10 @@ Ongoing

## Affected Products & Versions

- Palette VerteX 4.4.14
- Palette VerteX airgap 4.4.14

## Revision History

- 1.0 08/16/2024 Initial Publication
- 2.0 08/17/2024 Added Palette VerteX 4.4.14 to Affected Products
- 3.0 09/25/2024 CVE remediated in Palette VerteX 4.4.18
- 2.0 08/17/2024 Added Palette VerteX airgap 4.4.14 to Affected Products
- 3.0 09/25/2024 CVE remediated in Palette VerteX airgap 4.4.18
13 changes: 8 additions & 5 deletions docs/docs-content/security-bulletins/reports/cve-2016-20013.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,12 +35,15 @@ Ongoing

## Affected Products & Versions

- Palette VerteX 4.4.14, 4.4.18, 4.5.3
- Palette Enterprise 4.4.18, 4.5.3
- Palette VerteX airgap 4.4.14, 4.4.18, 4.5.3
- Palette Enterprise airgap 4.4.18, 4.5.3
- Palette VerteX 4.5.3
- Palette Enterprise 4.5.3

## Revision History

- 1.0 08/16/2024 Initial Publication
- 2.0 08/17/2024 Added Palette VerteX 4.4.14 to Affected Products
- 3.0 09/17/2024 Added Palette VerteX 4.4.18 & Palette Enterprise 4.4.18 to Affected Products
- 4.0 10/10/2024 Added Palette VerteX 4.5.3 & Palette Enterprise 4.5.3 to Affected Products
- 2.0 08/17/2024 Added Palette VerteX airgap 4.4.14 to Affected Products
- 3.0 09/17/2024 Added Palette VerteX airgap 4.4.18 & Palette Enterprise airgap 4.4.18 to Affected Products
- 4.0 10/10/2024 Added Palette VerteX airgap 4.5.3 & Palette Enterprise airgap 4.5.3 to Affected Products
- 5.0 10/14/2024 Added Palette Enterprise & Palette VerteX 4.5.3 to Affected Products
13 changes: 8 additions & 5 deletions docs/docs-content/security-bulletins/reports/cve-2017-11164.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,12 +35,15 @@ Ongoing

## Affected Products & Versions

- Palette VerteX 4.4.14, 4.4.18, 4.5.3
- Palette Enterprise 4.4.18, 4.5.3
- Palette VerteX airgap 4.4.14, 4.4.18, 4.5.3
- Palette Enterprise airgap 4.4.18, 4.5.3
- Palette VerteX 4.5.3
- Palette Enterprise 4.5.3

## Revision History

- 1.0 08/16/2024 Initial Publication
- 2.0 08/17/2024 Added Palette VerteX 4.4.14 to Affected Products
- 3.0 09/17/2024 Added Palette VerteX 4.4.18 & Palette Enterprise 4.4.18 to Affected Products
- 4.0 10/10/2024 Added Palette VerteX 4.5.3 & Palette Enterprise 4.5.3 to Affected Products
- 2.0 08/17/2024 Added Palette VerteX airgap 4.4.14 to Affected Products
- 3.0 09/17/2024 Added Palette VerteX airgap 4.4.18 & Palette Enterprise airgap 4.4.18 to Affected Products
- 4.0 10/10/2024 Added Palette VerteX airgap 4.5.3 & Palette Enterprise airgap 4.5.3 to Affected Products
- 5.0 10/14/2024 Added Palette Enterprise & Palette VerteX 4.5.3 to Affected Products
Original file line number Diff line number Diff line change
Expand Up @@ -38,10 +38,10 @@ Ongoing

## Affected Products & Versions

- Palette VerteX 4.4.14
- Palette VerteX airgap 4.4.14

## Revision History

- 1.0 08/16/2024 Initial Publication
- 2.0 08/17/2024 Added Palette VerteX 4.4.14 to Affected Products
- 3.0 09/25/2024 CVE remediated in Palette VerteX 4.4.18
- 2.0 08/17/2024 Added Palette VerteX airgap 4.4.14 to Affected Products
- 3.0 09/25/2024 CVE remediated in Palette VerteX airgap 4.4.18
13 changes: 8 additions & 5 deletions docs/docs-content/security-bulletins/reports/cve-2018-20657.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,12 +36,15 @@ Ongoing

## Affected Products & Versions

- Palette VerteX 4.4.14, 4.4.18, 4.5.3
- Palette Enterprise 4.4.18, 4.5.3
- Palette VerteX airgap 4.4.14, 4.4.18, 4.5.3
- Palette Enterprise airgap 4.4.18, 4.5.3
- Palette VerteX 4.5.3
- Palette Enterprise 4.5.3

## Revision History

- 1.0 08/16/2024 Initial Publication
- 2.0 08/17/2024 Added Palette VerteX 4.4.14 to Affected Products
- 3.0 09/17/2024 Added Palette VerteX 4.4.18 & Palette Enterprise 4.4.18 to Affected Products
- 4.0 10/10/2024 Added Palette VerteX 4.5.3 & Palette Enterprise 4.5.3 to Affected Products
- 2.0 08/17/2024 Added Palette VerteX airgap 4.4.14 to Affected Products
- 3.0 09/17/2024 Added Palette VerteX airgap 4.4.18 & Palette Enterprise airgap 4.4.18 to Affected Products
- 4.0 10/10/2024 Added Palette VerteX airgap 4.5.3 & Palette Enterprise airgap 4.5.3 to Affected Products
- 5.0 10/14/2024 Added Palette Enterprise & Palette VerteX 4.5.3 to Affected Products
13 changes: 8 additions & 5 deletions docs/docs-content/security-bulletins/reports/cve-2018-20796.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,12 +38,15 @@ Ongoing

## Affected Products & Versions

- Palette VerteX 4.4.14, 4.4.18, 4.5.3
- Palette Enterprise 4.4.18, 4.5.3
- Palette VerteX airgap 4.4.14, 4.4.18, 4.5.3
- Palette Enterprise airgap 4.4.18, 4.5.3
- Palette VerteX 4.5.3
- Palette Enterprise 4.5.3

## Revision History

- 1.0 08/16/2024 Initial Publication
- 2.0 08/17/2024 Added Palette VerteX 4.4.14 to Affected Products
- 3.0 09/17/2024 Added Palette VerteX 4.4.18 & Palette Enterprise 4.4.18 to Affected Products
- 4.0 10/10/2024 Added Palette VerteX 4.5.3 & Palette Enterprise 4.5.3 to Affected Products
- 2.0 08/17/2024 Added Palette VerteX airgap 4.4.14 to Affected Products
- 3.0 09/17/2024 Added Palette VerteX airgap 4.4.18 & Palette Enterprise airgap 4.4.18 to Affected Products
- 4.0 10/10/2024 Added Palette VerteX airgap 4.5.3 & Palette Enterprise airgap 4.5.3 to Affected Products
- 5.0 10/14/2024 Added Palette Enterprise & Palette VerteX 4.5.3 to Affected Products
13 changes: 8 additions & 5 deletions docs/docs-content/security-bulletins/reports/cve-2018-20839.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,12 +36,15 @@ Ongoing

## Affected Products & Versions

- Palette VerteX 4.4.14, 4.4.18, 4.5.3
- Palette Enterprise 4.4.18, 4.5.3
- Palette VerteX airgap 4.4.14, 4.4.18, 4.5.3
- Palette Enterprise airgap 4.4.18, 4.5.3
- Palette VerteX 4.5.3
- Palette Enterprise 4.5.3

## Revision History

- 1.0 08/16/2024 Initial Publication
- 2.0 08/17/2024 Added Palette VerteX 4.4.14 to Affected Products
- 3.0 09/17/2024 Added Palette VerteX 4.4.18 & Palette Enterprise 4.4.18 to Affected Products
- 4.0 10/10/2024 Added Palette VerteX 4.5.3 & Palette Enterprise 4.5.3 to Affected Products
- 2.0 08/17/2024 Added Palette VerteX airgap 4.4.14 to Affected Products
- 3.0 09/17/2024 Added Palette VerteX airgap 4.4.18 & Palette Enterprise airgap 4.4.18 to Affected Products
- 4.0 10/10/2024 Added Palette VerteX airgap 4.5.3 & Palette Enterprise airgap 4.5.3 to Affected Products
- 5.0 10/14/2024 Added Palette Enterprise & Palette VerteX 4.5.3 to Affected Products
46 changes: 46 additions & 0 deletions docs/docs-content/security-bulletins/reports/cve-2018-6829.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
---
sidebar_label: "CVE-2018-6829"
title: "CVE-2018-6829"
description: "Lifecycle of CVE-2018-6829"
hide_table_of_contents: true
sidebar_class_name: "hide-from-sidebar"
toc_max_heading_level: 2
tags: ["security", "cve"]
---

## CVE Details

[CVE-2018-6829](https://nvd.nist.gov/vuln/detail/CVE-2018-6829)

## Last Update

10/14/24

## NIST CVE Summary

Cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts,
which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic
security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for
Libgcrypt's ElGamal implementation.

## Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

## CVE Severity

[7.5](https://nvd.nist.gov/vuln/detail/CVE-2018-6829)

## Status

Ongoing

## Affected Products & Versions

- Palette Enterprise 4.5.3
- Palette VerteX 4.5.3

## Revision History

- 1.0 10/14/24 Initial Publication
- 2.0 10/14/2024 Added Palette Enterprise & Palette VerteX 4.5.3 to Affected Products
13 changes: 8 additions & 5 deletions docs/docs-content/security-bulletins/reports/cve-2019-1010022.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,12 +36,15 @@ Ongoing

## Affected Products & Versions

- Palette VerteX 4.4.14, 4.4.18, 4.5.3
- Palette Enterprise 4.4.18, 4.5.3
- Palette VerteX airgap 4.4.14, 4.4.18, 4.5.3
- Palette Enterprise airgap 4.4.18, 4.5.3
- Palette VerteX 4.5.3
- Palette Enterprise 4.5.3

## Revision History

- 1.0 08/16/2024 Initial Publication
- 2.0 08/17/2024 Added Palette VerteX 4.4.14 to Affected Products
- 3.0 09/17/2024 Added Palette VerteX 4.4.18 & Palette Enterprise 4.4.18 to Affected Products
- 4.0 10/10/2024 Added Palette VerteX 4.5.3 & Palette Enterprise 4.5.3 to Affected Products
- 2.0 08/17/2024 Added Palette VerteX airgap 4.4.14 to Affected Products
- 3.0 09/17/2024 Added Palette VerteX airgap 4.4.18 & Palette Enterprise airgap 4.4.18 to Affected Products
- 4.0 10/10/2024 Added Palette VerteX airgap 4.5.3 & Palette Enterprise airgap 4.5.3 to Affected Products
- 5.0 10/14/2024 Added Palette Enterprise & Palette VerteX 4.5.3 to Affected Products
13 changes: 8 additions & 5 deletions docs/docs-content/security-bulletins/reports/cve-2019-12900.md
Original file line number Diff line number Diff line change
Expand Up @@ -34,12 +34,15 @@ Ongoing

## Affected Products & Versions

- Palette VerteX 4.4.14, 4.4.18, 4.5.3
- Palette Enterprise 4.4.18, 4.5.3
- Palette VerteX airgap 4.4.14, 4.4.18, 4.5.3
- Palette Enterprise airgap 4.4.18, 4.5.3
- Palette VerteX 4.5.3
- Palette Enterprise 4.5.3

## Revision History

- 1.0 08/16/2024 Initial Publication
- 2.0 08/17/2024 Added Palette VerteX 4.4.14 to Affected Products
- 3.0 09/17/2024 Added Palette VerteX 4.4.18 & Palette Enterprise 4.4.18 to Affected Products
- 4.0 10/10/2024 Added Palette VerteX 4.5.3 & Palette Enterprise 4.5.3 to Affected Products
- 2.0 08/17/2024 Added Palette VerteX airgap 4.4.14 to Affected Products
- 3.0 09/17/2024 Added Palette VerteX airgap 4.4.18 & Palette Enterprise airgap 4.4.18 to Affected Products
- 4.0 10/10/2024 Added Palette VerteX airgap 4.5.3 & Palette Enterprise airgap 4.5.3 to Affected Products
- 5.0 10/14/2024 Added Palette Enterprise & Palette VerteX 4.5.3 to Affected Products
Original file line number Diff line number Diff line change
Expand Up @@ -36,9 +36,12 @@ Ongoing

## Affected Products & Versions

- Palette VerteX 4.4.14
- Palette VerteX airgap 4.4.14
- Palette VerteX 4.5.3
- Palette Enterprise 4.5.3

## Revision History

- 1.0 08/16/2024 Initial Publication
- 2.0 08/17/2024 Added palette VerteX 4.4.14 to Affected Products
- 2.0 08/17/2024 Added Palette VerteX airgap 4.4.14 to Affected Products
- 3.0 10/14/2024 Added Palette VerteX & Palette Enterptise 4.5.3 to Affected Products
Original file line number Diff line number Diff line change
Expand Up @@ -35,10 +35,13 @@ Ongoing

## Affected Products & Versions

- Palette VerteX 4.4.14
- Palette VerteX airgap 4.4.14
- Palette VerteX 4.5.3
- Palette Enterprise 4.5.3

## Revision History

- 1.0 08/16/2024 Initial Publication
- 2.0 08/17/2024 Added palette VerteX 4.4.14 to Affected Products
- 3.0 09/25/2024 CVE remediated in Palette VerteX 4.4.18
- 4.0 10/14/2024 Added Palette VerteX & Palette Enterptise 4.5.3 to Affected Products
Loading

0 comments on commit da67d29

Please sign in to comment.