GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Resolution This vulnerability impacts only the 11.38 Innovation Release and has been resolved in the following Innovation Update releases. All other versions are not affected. 11.38.20, which includes the fix as of April 10, 2025 11.38.25, which includes the fix as of April 10, 2025

Download link

https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/458/901/003/124/252/original/4d7dcf947b77b06c.png

Notices where this attachment appears

  1. Embed this notice
    Will Dormann (wdormann@infosec.exchange)'s status on Thursday, 08-May-2025 13:25:44 JST Will Dormann Will Dormann
    in reply to

    Now that I have a local copy of the Commvault VM so that I don't burn truckloads of Azure dollars, I can look at things at my leisure.

    AND, it seems that the VM that I have is 11.38.25, which contains the fix for CVE-2025-34028.

    EXCEPT the exploit for CVE-2025-34028 still works against it. 🤦♂️

    Commvault claims that 11.38.20 and 11.38.25 fixes the watchTowr-reported CVE-2025-34028 vulnerability. (Aside: How is it even possible that two different versions in the same product line are the ones that fix a single vulnerability?) watchTowr discovered the bug in 11.38.20.

    I trust watchTowr, so I don't believe Commvault's statement that 11.38.20 fixes the vulnerability that watchTowr found in 11.38.20.

    I also trust the PoC that I just ran against 11.38.25, so I don't believe Commvault's statement that 11.38.25 fixes the vulnerability that watchTowr found in 11.38.20.

    Yes, I have trust issues. 😕

    In conversation about 10 days ago from infosec.exchange permalink
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.