Jira (PDB-5000) Triage SEC-274 for PuppetDB and PE-PuppetDB

2021-03-08 Thread Austin Blatt (Jira)
Title: Message Title


 
 
 
 

 
 
 

 
   
 Austin Blatt updated an issue  
 

  
 
 
 
 

 
 
  
 
 
 
 

 
 PuppetDB /  PDB-5000  
 
 
  Triage SEC-274 for PuppetDB and PE-PuppetDB   
 

  
 
 
 
 

 
Change By: 
 Austin Blatt  
 
 
Security: 
 Internal  
 

  
 
 
 
 

 
 
 

 
 
 Add Comment  
 

  
 

  
 
 
 
  
 

  
 
 
 
 

 
 This message was sent by Atlassian Jira (v8.5.2#805002-sha1:a66f935)  
 
 

 
   
 

  
 

  
 

   





-- 
You received this message because you are subscribed to the Google Groups "Puppet Bugs" group.
To unsubscribe from this group and stop receiving emails from it, send an email to puppet-bugs+unsubscr...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/puppet-bugs/JIRA.383812.1611166106000.159969.1615228320037%40Atlassian.JIRA.


Jira (PDB-5000) Triage SEC-274 for PuppetDB and PE-PuppetDB

2021-01-20 Thread Austin Blatt (Jira)
Title: Message Title


 
 
 
 

 
 
 

 
   
 Austin Blatt updated an issue  
 

  
 
 
 
 

 
 
  
 
 
 
 

 
 PuppetDB /  PDB-5000  
 
 
  Triage SEC-274 for PuppetDB and PE-PuppetDB   
 

  
 
 
 
 

 
Change By: 
 Austin Blatt  
 

  
 
 
 
 

 
 Triage and provide a response to the CVE's in SEC-274 for pupetdb and pe-puppetdb clojure dependencies{noformat}Determining actual impact to the application based on how the packages   are being used is useful in applying the appropriate risk score therefore   some assistance is needed in determining actual impact to the application  (   ie, is the package utilizing the vulnerable paths). Please review the ticket   (SEC-274) for details and comment responses regarding use of packages   by 29 January 2021.{noformat}  
 

  
 
 
 
 

 
 
 

 
 
 Add Comment  
 

  
 

  
 
 
 
  
 

  
 
 
 
 

 
 This message was sent by Atlassian Jira (v8.5.2#805002-sha1:a66f935)  
 
 

 
   
 

  
 

  
 

   





-- 
You received this message because you are subscribed to the Google Groups "Puppet Bugs" group.
To unsubscribe from this group and stop receiving emails from it, send an email to puppet-bugs+unsubscr...@googlegroups.com.
To view this discussion on the web visit https://groups.google.

Jira (PDB-5000) Triage SEC-274 for PuppetDB and PE-PuppetDB

2021-01-20 Thread Austin Blatt (Jira)
Title: Message Title


 
 
 
 

 
 
 

 
   
 Austin Blatt updated an issue  
 

  
 
 
 
 

 
 
  
 
 
 
 

 
 PuppetDB /  PDB-5000  
 
 
  Triage SEC-274 for PuppetDB and PE-PuppetDB   
 

  
 
 
 
 

 
Change By: 
 Austin Blatt  
 

  
 
 
 
 

 
 Triage and provide a response to the CVE's in SEC-274 for pupetdb and pe-puppetdb clojure dependencies {noformat}Determining actual impact to the application based on how the packages are being used is useful in applying the appropriate risk score therefore some assistance is needed in determining actual impact to the application (ie, is the package utilizing the vulnerable paths). Please review the ticket (SEC-274) for details and comment responses regarding use of packages by 29 January 2021.{noformat}  
 

  
 
 
 
 

 
 
 

 
 
 Add Comment  
 

  
 

  
 
 
 
  
 

  
 
 
 
 

 
 This message was sent by Atlassian Jira (v8.5.2#805002-sha1:a66f935)  
 
 

 
   
 

  
 

  
 

   





-- 
You received this message because you are subscribed to the Google Groups "Puppet Bugs" group.
To unsubscribe from this group and stop receiving emails from it, send an email to puppet-bugs+unsubscr...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid

Jira (PDB-5000) Triage SEC-274 for PuppetDB and PE-PuppetDB

2021-01-20 Thread Austin Blatt (Jira)
Title: Message Title


 
 
 
 

 
 
 

 
   
 Austin Blatt created an issue  
 

  
 
 
 
 

 
 
  
 
 
 
 

 
 PuppetDB /  PDB-5000  
 
 
  Triage SEC-274 for PuppetDB and PE-PuppetDB   
 

  
 
 
 
 

 
Issue Type: 
  Task  
 
 
Assignee: 
 Austin Blatt  
 
 
Created: 
 2021/01/20 10:08 AM  
 
 
Priority: 
  Normal  
 
 
Reporter: 
 Austin Blatt  
 

  
 
 
 
 

 
 Triage and provide a response to the CVE's in SEC-274 for pupetdb and pe-puppetdb clojure dependencies  
 

  
 
 
 
 

 
 
 

 
 
 Add Comment  
 

  
 

  
 
 
 
  
 

  
 
 
 
 

 
 This message was sent by Atlassian Jira (v8.5.2#805002-sha1:a66f935)