Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability OS reporting inaccurate or not meaningful in Fleet #17110

Open
pacamaster opened this issue Feb 22, 2024 · 3 comments
Open

Vulnerability OS reporting inaccurate or not meaningful in Fleet #17110

pacamaster opened this issue Feb 22, 2024 · 3 comments
Assignees
Labels
~backend Backend-related issue. bug Something isn't working as documented customer-stazzema #g-endpoint-ops Endpoint ops product group :release Ready to write code. Scheduled in a release. See "Making changes" in handbook. ~released bug This bug was found in a stable release. ~vulnerability-management
Milestone

Comments

@pacamaster
Copy link
Member

pacamaster commented Feb 22, 2024

Fleet version:
Reported running in Fleet 4.44
Web browser and operating system:
Current release


💥  Actual behavior

The reported OS version is incomplete and lists lots of erroneous vulnerabilities for the OS. Taking all vulns and not seeming to exclude older versions in Fleet.
The tagged client has examples:
OS Windows 10 Pro 10.0.19045, which has CVEs dating back to 2021, but by looking at the full OS version of a sample host, it's actually 10.0.19045.3930, which is a Jan 2024 update. The information seems inconsistent or not too helpful.
image

When the version is correctly identified, is pulling 551 vulns for a most recent CU
image
And previous version reports same 551 vulns
image

Windows 11 seems to be fine, could be Windows 10 related
image

🧑‍💻  Steps to reproduce

  1. TODO

🕯️ More info (optional)

  • may be related to an older version of osquery (5.9.1) or hosts that have not checked in for a while.
  • Guess might be using host counts and numbers inflated or in error?
  • unable to reproduce in our Dogfood environment
    image
  • This could also be more of a feature request to make the info more clear what it is describing
@pacamaster pacamaster added bug Something isn't working as documented :reproduce Involves documenting reproduction steps in the issue #g-endpoint-ops Endpoint ops product group customer-stazzema :incoming New issue in triage process. labels Feb 22, 2024
@JoStableford
Copy link
Contributor

@pacamaster pacamaster added the ~released bug This bug was found in a stable release. label Feb 22, 2024
@pacamaster pacamaster removed ~released bug This bug was found in a stable release. #g-endpoint-ops Endpoint ops product group labels Feb 22, 2024
@sabrinabuckets sabrinabuckets added #g-endpoint-ops Endpoint ops product group :release Ready to write code. Scheduled in a release. See "Making changes" in handbook. ~vulnerability-management and removed :reproduce Involves documenting reproduction steps in the issue labels Feb 23, 2024
@lukeheath lukeheath added the ~released bug This bug was found in a stable release. label Feb 23, 2024
@sharon-fdm sharon-fdm removed the :incoming New issue in triage process. label Feb 29, 2024
@sharon-fdm
Copy link
Contributor

sharon-fdm commented Feb 29, 2024

@pacamaster could you please provide reproduction steps?

@sharon-fdm sharon-fdm added :reproduce Involves documenting reproduction steps in the issue and removed :reproduce Involves documenting reproduction steps in the issue labels Feb 29, 2024
@sharon-fdm sharon-fdm added the ~backend Backend-related issue. label Mar 6, 2024
@lukeheath lukeheath modified the milestones: 4.48.0-tentative, 4.47.0-tentative Mar 11, 2024
@mostlikelee
Copy link
Contributor

I could not replicate the issue of Win10 hosts not reporting the full OS version (via osquery 5.9.1 or 5.11), but I added extra validation for offline hosts that have not yet reported correctly since an upgrade to 4.44.0+ to the scope.

Additionally I found a bug where osquery is not correctly reporting the Win10 build version in the kernel_info table. This is also added to the scope.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
~backend Backend-related issue. bug Something isn't working as documented customer-stazzema #g-endpoint-ops Endpoint ops product group :release Ready to write code. Scheduled in a release. See "Making changes" in handbook. ~released bug This bug was found in a stable release. ~vulnerability-management
Development

No branches or pull requests

7 participants