まっちゃだいふくの日記

セキュリティのこと、ITの気になった記事をリンクしています。

Deep Security 12.0 update 22 (DS 20U22)リリース@ AWS instance IDをイベントに入れられるって良いな。

Deep Security Manager - 12.0 update 22

Deep Security Manager - 12.0 update 22
Release date: November 01, 2021
Build number: 12.0.521

Enhancements

  • Updated Deep Security Manager to allow adding the AWS instance ID field in system and security events using a (dsm_c) console command. SEG-109291/SF04487365/DSSEG-7055

Resolved issues

  • Deep Security Manager sometimes received alerts for agents that had not been activated. SEG-112134/SF04588645/DSSEG-6962

Security updates

Security updates are included in this release. For more information about how we protect against vulnerabilities, visit Vulnerability Responses. Please note, in line with responsible disclosure practices, CVE details will only be made available for select security updates once patches have been made available for all impacted releases. VRTS-6534/04742276/DSSEG-7231

  • Highest CVSS: 6.1
  • Highest severity: Medium
What's new in Deep Security Manager? | Deep Security

Deep Security Linux Agent - 12.0 update 22

Deep Security Agent - 12.0 update 22
Release date: November 01, 2021
Build number: 12.0.0-2072

Enhancements

  • Updated Deep Security Agent to prevent agents upgraded from version 10.0 to 12.0 from losing their "NIC bypass" configuration (used for Bypassing a network interface). SEG-111757/SF04574021/DSSEG-7087

Resolved issues

  • Deep Security Agent sometimes showed package signature errors during an upgrade because of a mismatched Certification Revocation List (CRL). DSSEG-7214
  • A plugin version conflict sometimes prevented Deep Security Agent from retrieving KSP (Kernel Support Package) files from the relay. DSSEG-7244
  • Deep Security Agent sometimes crashed due to an issue when cleaning up resources for inactive network connections. SEG-113291/DSSEG-7035
  • If the Deep Security Agent service (ds_agent) was stopped during an Anti-Malware scan, the agent would sometimes crash on restart. DSSEG-7228

Security updates

Security updates are included in this release. For more information about how we protect against vulnerabilities, visit Vulnerability Responses. Please note, in line with responsible disclosure practices, CVE details will only be made available for select security updates once patches have been made available for all impacted releases. VRTS-6489/DSSEG-7237

  • Highest CVSS: 7.8
  • Highest severity: High
What's new in Deep Security Agent? | Deep Security

Deep Security Windows Agent - 12.0 update 22

Deep Security Agent - 12.0 update 22
Release date: November 01, 2021
Build number: 12.0.0-2072

Resolved issues

  • Deep Security Agent sometimes showed package signature errors during an upgrade because of a mismatched Certification Revocation List (CRL). DSSEG-7214
  • A plugin version conflict sometimes prevented Deep Security Agent from retrieving KSP (Kernel Support Package) files from the relay. DSSEG-7244
  • Deep Security Agent sometimes crashed due to an issue when cleaning up resources for inactive network connections. SEG-113291/DSSEG-7035
  • If the Deep Security Agent service (ds_agent) was stopped during an Anti-Malware scan, the agent would sometimes crash on restart. DSSEG-7228

Security updates

Security updates are included in this release. For more information about how we protect against vulnerabilities, visit Vulnerability Responses. Please note, in line with responsible disclosure practices, CVE details will only be made available for select security updates once patches have been made available for all impacted releases. VRTS-6489/DSSEG-7237

  • Highest CVSS: 7.8
  • Highest severity: High
What's new in Deep Security Agent? | Deep Security

Deep Security UNIX Agent - 12.0 update 22

Deep Security Agent - 12.0 update 22
Release date: November 01, 2021
Build number: 12.0.0-2072

Resolved issues

  • Deep Security Agent sometimes showed package signature errors during an upgrade because of a mismatched Certification Revocation List (CRL). DSSEG-7214
  • Deep Security Agent sometimes crashed due to an issue when cleaning up resources for inactive network connections. SEG-113291/DSSEG-7035
  • If the Deep Security Agent service (ds_agent) was stopped during an Anti-Malware scan, the agent would sometimes crash on restart. DSSEG-7228

Security updates

Security updates are included in this release. For more information about how we protect against vulnerabilities, visit Vulnerability Responses. Please note, in line with responsible disclosure practices, CVE details will only be made available for select security updates once patches have been made available for all impacted releases. VRTS-6489/DSSEG-7237

  • Highest CVSS: 7.8
  • Highest severity: High
What's new in Deep Security Agent? | Deep Security