PAN-SA-2024-0002 Impact of Leaky Vessels Vulnerabilities (CVE-2024-21626, CVE-2024-23651, CVE-2024-23652, and CVE-2024-23653)
🔗 CVE IDs covered (4)
📋 Description
The Palo Alto Networks Product Security Assurance team has evaluated the four vulnerabilities in Open Container Initiative's runc and Moby BuildKit software (collectively known as "Leaky Vessels") as it relates to our products. While Cortex XSOAR 8, Cortex XSOAR 6 Hosted, and Prisma Cloud Compute rely on this software, they do not offer any scenarios required for the successful exploitation of these vulnerabilities and are not impacted. Cortex XSOAR 6 On Premise deployments using Docker 25.0.2 or later are not impacted. At present, no other Palo Alto Networks products are known to contain the vulnerable software packages and be impacted by these issues. Protecting our customers is our highest priority. Palo Alto Networks and its Unit 42 threat research team have closely monitored all developments. You can find technical details, regular updates and guidance here: https://www.paloaltonetworks.com/blog/prisma-cloud/leaky-vessels-vulnerabilities-container-escape/.
🎯 Affected products2
- Cortex XSOAR
- Prisma Cloud Compute
✅ Remediation
Cortex XSOAR 6 On Premise deployments should ensure use of Docker 25.0.2 or higher. For additional guidance in hardening Docker with Cortex XSOAR, please see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.5/Cortex-XSOAR-Administrator-Guide/Docker-Hardening-Guide.