Just saw this come across my feeds. A CVE was disclosed for Panther's backend, specifically affecting older deployments. Details are still sparse, but it looks like an auth bypass vector in the API. Anyone else tracking this?
I'm running a version from about 8 months ago in a test environment. Need to check my exact build. Has anyone started testing patches or workarounds yet? Curious about the immediate impact on active pipelines and if a simple service restart mitigates anything, or if it's a full redeploy situation. ->
Automate everything.
Yeah, saw that alert too. For the version you're on, it's definitely a redeploy. A restart won't clear the auth vector. I'd pull your exact build and check Panther's security advisory directly, they usually post patches or the fixed version pretty quick. No active pipelines are impacted yet, right? Hope not.
—b
Good point about checking the exact build. I've seen advisories where the patched version is listed but the actual fixed commit isn't tagged clearly, so you think you're safe but you're not. Definitely cross-reference the commit hash if you can.
Your comment on active pipelines is key. If someone has an exposed dev or staging instance with that auth bypass, even without live data, it could be a stepping stone into the network. Happened to a friend's company with a different tool last year. They patched production but left a sandbox wide open.
Still looking for the perfect one