From 73bf0b17d7c2dfd0eec39e4f7a74989052d5d2f3 Mon Sep 17 00:00:00 2001 From: Desmi-Dizney <99777687+Desmi-Dizney@users.noreply.github.com> Date: Tue, 17 May 2022 11:22:31 -0500 Subject: [PATCH] Editor pass - Publish pentest blog + Security-audits.md section (#5773) Editor pass for: - https://github.com/fleetdm/fleet/pull/5659 --- articles/security-testing-at-fleet-fleet-pentest.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/articles/security-testing-at-fleet-fleet-pentest.md b/articles/security-testing-at-fleet-fleet-pentest.md index f03c143658..9520ef320b 100644 --- a/articles/security-testing-at-fleet-fleet-pentest.md +++ b/articles/security-testing-at-fleet-fleet-pentest.md @@ -1,7 +1,7 @@ # Penetration testing of Fleet (April 2022) -We have recently had Lares perform penetration testing on our internal instance of Fleet. This test was performed on 4.12 It’s the test that unveiled some authorization issues identified in this [advisory](https://github.com/fleetdm/fleet/security/advisories/GHSA-pr2g-j78h-84cr) and resolved in 4.13. +We have recently had Lares perform penetration testing on our internal instance of Fleet. Lares performed the last test on 4.12. This test unveiled some authorization issues identified in this [advisory](https://github.com/fleetdm/fleet/security/advisories/GHSA-pr2g-j78h-84cr) and resolved in 4.13. -As promised when we published the [Orbit audit](https://github.com/fleetdm/fleet/blob/26daf00e5a8ce509371f33065ebf06eecf50c557/docs/files/2021-04-26-orbit-auto-updater-assessment.pdf) and said we’d post other audit and pentest reports, we are now publishing the full report. The most critical issues have been resolved in 4.13, and others are being tracked and prioritized. +As promised when we published the [Orbit audit](https://github.com/fleetdm/fleet/blob/26daf00e5a8ce509371f33065ebf06eecf50c557/docs/files/2021-04-26-orbit-auto-updater-assessment.pdf) and said we’d post other audit and pentest reports, we are now publishing the full report. We resolved the most critical issues in 4.13, and we continue to track and prioritize the others. Small redacted sections are present in the PDF as we are hiding some internal email addresses to save ourselves from receiving more spam. @@ -36,4 +36,4 @@ If you have questions about this test or Fleet security, please join us on [Slac - \ No newline at end of file +