fleet icon indicating copy to clipboard operation
fleet copied to clipboard

Potential false positives for CVEs related to Google Chrome in Fleet 4.51.0

Open ddribeiro opened this issue 1 year ago • 1 comments

Fleet version: 4.51.0


💥  Actual behavior

A customer is reporting that CVEs are being reported for a version of Google Chrome that has already been patched. Attached screen shots show multiple CVEs related to Chrome appearing 829 times in the Fleet environment even though all hosts (274) were patched with a version of Chrome. This CVE should no longer be appearing in Fleet.

IMG_1116 IMG_1117

🕯️ More info (optional)

The CVEs in question appear in Dogfood but the numbers appear to be accurate. I am attempting to get a screenshot of what the CVE detail page looks like in the customer’s environment to learn more about what software pieces they apply to and if versions of Chrome are that don’t actually appear in the environment are being reported.

ddribeiro avatar Jun 27 '24 16:06 ddribeiro

Hey team! Please add your planning poker estimate with Zenhub @getvictor @jacobshandling @lucasmrod @mostlikelee @RachelElysia

sharon-fdm avatar Jul 03 '24 14:07 sharon-fdm

Timebox 2 points to reproduce.

sharon-fdm avatar Jul 15 '24 18:07 sharon-fdm

@ddribeiro cleanups for vulnerabilities runs every 2 * periodicity (1hr being the default periodicity for the vulnerability cron). So, found vulnerabilities that no longer apply are deleted at that time. Could this be what we're running into here?

mostlikelee avatar Aug 22 '24 16:08 mostlikelee

@ddribeiro was there any follow up to this issue? If not we'll be closing it out as stale. Thank you!

xpkoala avatar Sep 09 '24 16:09 xpkoala

@xpkoala The customer responded to my thread last night with a link to schedule a troubleshooting call. I think we're going to set something up to learn more details about the behavior and report back.

ddribeiro avatar Sep 09 '24 17:09 ddribeiro

@xpkoala We can go ahead and close this issue. We haven't been able to get more info on the customer side of things.

cc: @mostlikelee

ddribeiro avatar Sep 16 '24 15:09 ddribeiro

Chrome patched, yet still, CVEs echo wrongly, Fleet's truth will dispel.

fleet-release avatar Sep 16 '24 15:09 fleet-release