Skip to content

Conversation

kakabisht
Copy link
Contributor

No description provided.

Copy link
Contributor

@sunilarjun sunilarjun left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the PR @kakabisht! Left some edit comments below, but some other changes are needed on this page that I'll note here:

The note on lines 42-44 needs editing, suggesting:

NeuVector installations that have the single sign-on integration with Rancher Manager and the Remote Repository Configuration disabled are not affected by this issue.

The phrasing of line 46 I think should be updated as well, suggestiong below:

In the patched version, X-R-Sess is partially masked so that users can confirm what is being used while still keeping it safe for consumption. The log, which includes `personal_access_token`, `token`, `rekor_public_key`, `root_cert`, `sct_public_key`, and `public key` are removed, as the request body is not mandatory in the log.

The note on line 48 needs the closing ::: after line 52.

The bullet points are erroring from lines 66-70. Suggestion below:

* Contact the [SUSE Rancher Security team](https://github.com/rancher/rancher/security/policy).
* Open an issue in the [NeuVector GitHub repository](https://github.com/neuvector/neuvector/issues/new/choose).
* References:
  * [NeuVector Support Matrix](https://www.suse.com/suse-neuvector/support-matrix/all-supported-versions/neuvector-v-all-versions/)
  * [Product Support Lifecycle](https://www.suse.com/lifecycle/#suse-security)

These changes will also need to be applied to the page in the 5.4 folder as well. Please let me know if you have any questions, thanks!

@kakabisht kakabisht marked this pull request as ready for review September 21, 2025 18:22
@kakabisht kakabisht merged commit 8f24b49 into neuvector:main Sep 21, 2025
@kakabisht kakabisht deleted the fix-cve-5.4.4 branch September 21, 2025 18:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants