Skip to main content

July 2024

CVE-2024-6387 - Qualys Security Advisory - Update Advisory

Additional information

Further technical details about this issue may be found in the Qualys writeup of this issue.

SUNK/Slurm User Guidance

Clients who are not on a CoreWeave-managed instance of SUNK and who meet the criteria below should take action to ensure that SUNK is patched against CVE-2024-6387:
  • Are using SUNK versions 3.20.0 through 4.3.0
  • Are using Ubuntu images in SUNK of 22.04 or higher
If the criteria above are met, clients should take the following actions:
  • Add the following items to the s6 configuration for both login and compute Nodes in the chart values.yaml being used to deploy CoreWeave’s Slurm chart:
  • Deploy these changes (if using ArgoCD, sync the changes with the cluster).
This will roll the NodeSet Pods for the compute Nodes. If login StatefulSets are set to use the OnDelete update strategy, then the login Pods to all that will be upgraded with these changes will need to be manually deleted. See the official Kubernetes documentation on StatefulSet update strategies for more information.
If using custom build images for SUNK, these commands can be integrated into the image build instead.

November 2023

CVE-2023-23583 - INTEL-SA-00950 Update Advisory

CoreWeave’s Vulnerability Management Team is closely monitoring the situation and is dedicated to providing timely updates if deemed necessary. If required, updates to this page will be posted.

December 2022

CVE-2022-42475

FortiGuard Labs has confirmed at least one instance of vulnerability CVE-2022-42475 being exploited in the wild. Given the high value (CVE critical severity rating 9.3) and relatively low complexity of this vulnerability, CoreWeave strongly recommends upgrading to an unaffected version of FortiOS on an accelerated patch schedule, according to vendor recommendations. Vulnerability checks for CVE-2022-42475 are available from a variety of sources. Please use caution when running any script or application to ensure it is safe. At this time there is no impact to CoreWeave’s platform, however customers who have FortiOS running within their environment are advised to review the vendor-recommended mitigations, and take appropriate self measures to upgrade their deployments and evaluate their systems for any indicators of compromise. Our cyber security team is closely monitoring the situation, and will provide important updates should more information become available.