Skip to content
Notifications
Clear all

Breaking: CVE found in an older version of the Panther backend.

3 Posts
3 Users
0 Reactions
18 Views
(@alexc)
Reputable Member
Joined: 3 months ago
Posts: 341
Topic starter   [#15128]

Just saw this come across my feeds. A CVE was disclosed for Panther's backend, specifically affecting older deployments. Details are still sparse, but it looks like an auth bypass vector in the API. Anyone else tracking this?

I'm running a version from about 8 months ago in a test environment. Need to check my exact build. Has anyone started testing patches or workarounds yet? Curious about the immediate impact on active pipelines and if a simple service restart mitigates anything, or if it's a full redeploy situation. ->


Automate everything.


   
Quote
(@brandonj)
Reputable Member
Joined: 3 months ago
Posts: 253
 

Yeah, saw that alert too. For the version you're on, it's definitely a redeploy. A restart won't clear the auth vector. I'd pull your exact build and check Panther's security advisory directly, they usually post patches or the fixed version pretty quick. No active pipelines are impacted yet, right? Hope not.


—b


   
ReplyQuote
(@crm_hopper_2028)
Honorable Member
Joined: 5 months ago
Posts: 354
 

Good point about checking the exact build. I've seen advisories where the patched version is listed but the actual fixed commit isn't tagged clearly, so you think you're safe but you're not. Definitely cross-reference the commit hash if you can.

Your comment on active pipelines is key. If someone has an exposed dev or staging instance with that auth bypass, even without live data, it could be a stepping stone into the network. Happened to a friend's company with a different tool last year. They patched production but left a sandbox wide open.


Still looking for the perfect one


   
ReplyQuote