32.xx Known Issues
The following table lists the known issues for 32.00 release.
Known Issues
ISSUE ID
DESCRIPTION
CWP-59435
Enabling FIPS with TLS 1.3 does not work for WAAS In-Line
Due to a compatibility issue in Go programming language’s package, the HTTP server is unable to operate with both FIPS mode and TLS 1.3 enabled simultaneously. This limitation is preventing WAAS In-Line from supporting the configuration.
CWP-53375
In Inventory > Compute Workloads, for users logged in with a role other than the built-in system admin role, currently only data about cloud provider managed registry images and VM instances can be viewed.
In particular, for such roles currently data about the following types of assets is not displayed:
Run stage images
Private registry images
Build stage images
On-premises hosts/hosts managed by cloud providers unsupported by Compute
CWP-58896
With the support for ACI in cloud discovery, here are the two issues:
Status: The
statusfield currently utilizes Properties > ProvisioningState, which does not reflect the container status. For more information, refer to Azure Container Instances states.Defend: The Defend functionality does not support Azure Container Instances (ACI). The Defend is enabled across all accounts and services, and when selected, it redirects to Images > Registry Settings.
CWP-58709
Duplicate Admission Rules
Six admission rules released in Version 32, Update 2 were found to be duplicates of older existing rules. If you need the functionality provided by these rules, we recommend disabling the old rules and using the new corresponding rules, as the older rules will be removed in an upcoming release.
The old rules and their corresponding new rules are as follows:
Old rule: Twistlock Labs - CIS - Pod created in host process ID namespace. New rule: Twistlock Labs - PSS - Baseline - Pod with containers that share host process ID (hostPID) namespace
Old rule: Twistlock Labs - CIS - Pod created on host IPC namespace. New rule: Twistlock Labs - PSS - Baseline - Pod with containers that share host IPC namespace
Old rule: Twistlock Labs - CIS - Pod created on host network. New rule: Twistlock Labs - PSS - Baseline - Pod that allows containers to share the host network namespace
Old rule: Twistlock Labs - Pod created with sensitive host file system mount. New rule: Twistlock Labs - PSS - Baseline - Pod created with sensitive host file system mount
Old rule: Twistlock Labs - CIS - Privileged pod created. New rule: Twistlock Labs - PSS - Baseline - Pod should not run privileged containers
Old rule: Twistlock Labs - CIS - Privilege escalation pod created. New rule: Twistlock Labs - PSS - Restricted - Pod that allows container privilege escalation
Note: Even though both the new and old rules are enabled by default, you will not receive duplicate alerts as only the first encountered rule is enforced.
CWP-58350
CVE Exclusions Update
The following CVEs that are included in the Intelligence Stream feed are ignored:
CVE-2022-29583 - GitHub Advisory Database as it is a disputed vulnerability.
CVE-2024-3154 - Arbitrary Systemd Property Injection as Defender does not directly use this package.
CWP-52710
While upgrading consoles from the 30.03 release to a 32.xx release, the error log failed to retrieve "size" specification option value during the migration doesn’t impact the migration process and can be ignored.
Last updated
Was this helpful?

