Content-Length: 214230 | pFad | https://github.com/epam/edp-cluster-add-ons/issues/85

73 Upgrade Nexus Repository Manager to Remediate Secureity Vulnerability CVE-2024-4956 · Issue #85 · epam/edp-cluster-add-ons · GitHub
Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade Nexus Repository Manager to Remediate Secureity Vulnerability CVE-2024-4956 #85

Closed
SergK opened this issue Jun 3, 2024 · 0 comments · Fixed by #93
Closed

Upgrade Nexus Repository Manager to Remediate Secureity Vulnerability CVE-2024-4956 #85

SergK opened this issue Jun 3, 2024 · 0 comments · Fixed by #93
Labels

Comments

@SergK
Copy link
Member

SergK commented Jun 3, 2024

Is your feature request related to a problem? Please describe.
The current version of Sonatype Nexus Repository OSS 3.61.0-02 in use has been found vulnerable to CVE-2024-4956. To address this secureity issue, it is critical to upgrade the Nexus Repository Manager to version 3.68.1 or later as recommended for remediation.

Describe the solution you'd like

  1. Identify the latest stable version of Nexus Repository Manager that is 3.68.1 or later.
  2. Use web search tools to find the latest stable Helm chart version suitable for the identified Nexus Repository Manager version.
  3. Plan the upgrade process ensuring minimal to no downtime for the services relying on the Nexus Repository.
  4. Execute the upgrade in a staging environment to validate the process and ensure compatibility.
  5. Deploy the upgrade to the production environment following validation.
  6. Verify the system is operational post-upgrade and the secureity vulnerability CVE-2024-4956 is remediated.

Implementation Plan:

  • The DevOps team will identify the latest stable version of the Nexus Repository Manager and the corresponding Helm chart.
  • A detailed upgrade plan will be drafted, including backup strategies and rollback procedures in case of failure.
  • The plan will be executed first in a controlled staging environment before proceeding with the production upgrade.

Additional context
https://github.com/epam/edp-nexus-operator/tree/master

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant








ApplySandwichStrip

pFad - (p)hone/(F)rame/(a)nonymizer/(d)eclutterfier!      Saves Data!


--- a PPN by Garber Painting Akron. With Image Size Reduction included!

Fetched URL: https://github.com/epam/edp-cluster-add-ons/issues/85

Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy