Hello,I have query regarding Prisma showing vulnerabilities in ubuntu OS nodes. My ubuntu release is 18.04.6 LTS Bionic Beaver
1. Prisma is showing this vulnerability CVE-2022-1664.. in installed dpkg version 1.19.05 and suggesting to install 1.20.10... Where as this is already resolved in 1.19.05 as shown here https://ubuntu.com/security/CVE-2022-1664
2. ~Prisma is showing this vulnerability CVE-2022-1292.. in installed openssl version 1.1.1-1ubuntu2.1~18.04.19 and suggesting to install 1.1.1n-0+deb11u2.. Where as this is already resolved in 1.1.1-1ubuntu2.1~18.04.17 as shown here url ~
Tanul
06/28/2022, 6:30 PM
One more thing wanted to highlight w.r.t. point 1st. dpkg 1.20.10 doesn't exisit as per my understanding. For more details.. we can refer here.. How prisma is suggesting.. Am I understanding it wrong::https://launchpad.net/ubuntu/+source/dpkg
@janpio, Oh I'm extremely sorry.. Which channel is for prisma cloud defender
v
Vladi Stevanovic
06/29/2022, 10:03 AM
@Tanul to clarify you're talking about a product provided by a different company: https://docs.paloaltonetworks.com/prisma/prisma-cloud
We're a different company and this Slack community is only dedicated to our products (i.e. Prisma ORM ecosystem).