-
Notifications
You must be signed in to change notification settings - Fork 1.3k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request #18078 from newrelic/rhs-NR24-02-OpenSSH
Security: Add new bulletin for NR24-02
- Loading branch information
Showing
3 changed files
with
88 additions
and
5 deletions.
There are no files selected for viewing
43 changes: 43 additions & 0 deletions
43
...cs/security/new-relic-security/security-bulletins/security-bulletin-nr24-02.mdx
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,43 @@ | ||
--- | ||
title: "NR24-02 - OpenSSH in New Relic Salesforce Exporter" | ||
tags: | ||
- Security | ||
- Security bulletin | ||
- Salesforce Exporter | ||
metaDescription: "Security bulletin for all customers using the New Relic Salesforce Exporter." | ||
releaseDate: '2024-07-18' | ||
--- | ||
|
||
<DNT>**Vulnerability Identifier:**</DNT> NR24-02 | ||
|
||
<DNT>**Priority:**</DNT> High | ||
|
||
## Summary | ||
|
||
New Relic advises all customers using the New Relic Salesforce Exporter to update to version 2.2.0, which New Relic has released to eliminate a recently announced [vulnerable version of OpenSSH](https://nvd.nist.gov/vuln/detail/CVE-2024-6387). | ||
|
||
## Action required | ||
|
||
New Relic is recommending that customers who use the New Relic Salesforce Exporter immediately update to version 2.2.0. | ||
|
||
New Relic has provided the following resources to assist with these updates: | ||
|
||
* [Salesforce Exporter Release Notes](https://github.com/newrelic/newrelic-salesforce-exporter/releases/tag/2.2.0) | ||
* [Detecting & Upgrading on-host deployments](https://github.com/newrelic/newrelic-salesforce-exporter?tab=readme-ov-file#upgrading-on-host-deployments) | ||
|
||
If customers are unable to upgrade their New Relic Salesforce Exporter, limit SSH access through network-based controls to minimize the attack risks. | ||
|
||
|
||
|
||
## Supporting Release Notes | ||
|
||
[Salesforce Exporter Release Notes](https://github.com/newrelic/newrelic-salesforce-exporter/releases/tag/2.2.0) | ||
|
||
## Technical vulnerability information | ||
|
||
[CVE-2024-6387](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6387) | ||
|
||
## Publication History | ||
|
||
July 18, 2024 - NR24-02 Published | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters