Skip to content

Latest commit

 

History

History
82 lines (59 loc) · 1.99 KB

security-bulletin-nr19-01.mdx

File metadata and controls

82 lines (59 loc) · 1.99 KB
title tags metaDescription redirects releaseDate
Security Bulletin NR19-01
Security
Security and Privacy
Security bulletins
Security vulnerability update for New Relic .NET agent.
/docs/using-new-relic/new-relic-security/security-bulletins/security-bulletin-nr19-01
2020-12-10

Summary

A security update for the .NET agent corrects an issue where query strings may be captured when using OpenRasta instrumentation.

Release date: January 9, 2019

Vulnerability identifier: NR19-01

Priority: Medium

Affected software [#affected]

The following New Relic agent versions are affected:

  <th>
    Affected version
  </th>

  <th>
    Notes
  </th>

  <th>
    Remediated version
  </th>
</tr>
  <td>
    &lt;8.12.216.0
  </td>

  <td/>

  <td>
    8.12.216.0
  </td>
</tr>
Name
.NET agent

Vulnerability information [#vuln-info]

When using OpenRasta instrumentation, the full URL may be captured on instrumented requests. This may result in query strings being collected which can contain sensitive information

Mitigating factors [#factors]

This vulnerability only exists when using OpenRasta instrumentation.

Workarounds

Report security vulnerabilities to New Relic [#report]

New Relic is committed to the security of our customers and their data. If you believe you have found a security vulnerability in one of our products or websites, we welcome and greatly appreciate you reporting it to New Relic's coordinated disclosure program. For more information, see Reporting security vulnerabilities.