Skip to content

Commit 57ee382

Browse files
authored
Merge pull request #205196 from bmansheim/omi-vulnerability
Add release note for protecting against CVE-2022-29149
2 parents 7ffa4b6 + 4075ab3 commit 57ee382

File tree

1 file changed

+9
-0
lines changed

1 file changed

+9
-0
lines changed

articles/defender-for-cloud/release-notes.md

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,7 @@ Updates in July include:
2222

2323
- [General availability (GA) of the Cloud-native security agent for Kubernetes runtime protection](#general-availability-ga-of-the-cloud-native-security-agent-for-kubernetes-runtime-protection)
2424
- [Defender for Container's VA adds support for the detection of language specific packages (Preview)](#defender-for-containers-va-adds-support-for-the-detection-of-language-specific-packages-preview)
25+
- [Protect against the Operations Management Suite vulnerability CVE-2022-29149](#protect-against-the-operations-management-suite-vulnerability-cve-2022-29149)
2526

2627
### General availability (GA) of the Cloud-native security agent for Kubernetes runtime protection
2728

@@ -51,6 +52,14 @@ This feature is in `preview` and is only available for Linux images.
5152

5253
To see all of the included language specific packages that have been added, check out Defender for Container's full list of [features and their availability](supported-machines-endpoint-solutions-clouds-containers.md#registries-and-images).
5354

55+
### Protect against the Operations Management Suite vulnerability CVE-2022-29149
56+
57+
Operations Management Suite (OMS) is a collection of cloud-based services for managing on-premises and cloud environments from one single place. Rather than deploying and managing on-premises resources, OMS components are entirely hosted in Azure.
58+
59+
Log Analytics integrated with Azure HDInsight running OMS version 13 requires a patch to remediate [CVE-2022-29149](https://nvd.nist.gov/vuln/detail/CVE-2022-29149). Review the report about this vulnerability in the [Microsoft Security Update guide](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-29149) for information about how to identify resources that are affected by this vulnerability and remediation steps.
60+
61+
If you have Defender for Servers enabled with Vulnerability Assessment, you can use [this workbook](https://github.com/Azure/Microsoft-Defender-for-Cloud/tree/main/Workbooks/OMI%20Vulnerability%20Dashboard) to identify affected resources.
62+
5463
## June 2022
5564

5665
Updates in June include:

0 commit comments

Comments
 (0)