September 2024 Summaries
2 posts from Replicated
Filter
Month:
Year:
Post Summaries
Back to Blog
On September 23, a researcher disclosed a critical CVSSv3 9.9 score unauthenticated remote code execution vulnerability affecting "all GNU/Linux systems," specifically targeting the Common UNIX Printing System (CUPS), with identified vulnerabilities labeled as CVE-2024-47076, CVE-2024-47175, CVE-2024-47176, and CVE-2024-47177. Replicated assessed its systems and deemed the risk low, as their products do not start the CUPS service by default, and are built on "distroless" images that support daily automated rebuilds. However, Kurl, which uses Alpine Linux, may need patching once updates are available. They recommend users keep their systems updated, minimize unnecessary packages, and ensure firewall protections, with plans to release new product versions following the availability of patches.
Sep 27, 2024
436 words in the original blog post.
The September 2024 Replicated Monthly Release introduces several updates aimed at enhancing compatibility, security, and user experience. The Compatibility Matrix now supports Kubernetes 1.31 on kind clusters, and improvements in the Replicated CLI enable tab autocomplete for cluster IDs and names. A new Vendor API v3 feature allows filtering customer instances by channel ID, sequence, and version label, streamlining compatibility testing. The Embedded Cluster BETA now performs host preflight checks before installation, expands the default NodePorts range, and builds images with Chainguard for improved security. Additionally, updates to KOTS Config introduce a new dropdown item type, and streamline domain verification in the Vendor Portal. Troubleshoot v0.99.0 includes an etcd collector for improved issue resolution, while new documentation assists vendors in finding customer-specific installation commands.
Sep 04, 2024
796 words in the original blog post.