> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/ce-release-notes/32/prisma-tm-cloud-compute-edition-release-information/release-notes-32-07.md).

# 32.07 (Build 32.07.123)

The following table outlines the release particulars:

| Build        | 32.07.123                                                        |
| ------------ | ---------------------------------------------------------------- |
| Code name    | O’Neal - Update 7, 32.07                                         |
| Release date | July 22nd, 2024                                                  |
| Type         | Maintenance Release                                              |
| SHA-256      | 579c449ef5137673dcb2a81da6cdbdf2d1e754c1b5b4018f72821a065136df7d |

Review the [system requirements](https://docs.prismacloud.io/en/compute-edition/32/admin-guide/install/system-requirements) to learn about the supported operating systems, hypervisors, runtime, tools, and orchestrators.

## Upgrade from Previous Releases

### Upgrade Defender Versions

With the v32.xx release, the [supported (n, n-1, and n-2) Defender versions](https://docs.prismacloud.io/en/compute-edition/32/admin-guide/upgrade/support-lifecycle) are v32.xx, v31.xx, and v30.xx. Defender versions below v30.xx such as v22.12 cannot connect to the current version.

### Upcoming Defender Obsolescence

With the upcoming v33.00 release, release v30.xx defenders will be obsolete. To prepare for this upcoming update, plan to upgrade defenders to release v31.xx or later.

### Upgrade the Prisma Cloud Console

With the v32.xx release, the [supported (n, n-1, and n-2) Console versions](https://docs.prismacloud.io/en/compute-edition/32/admin-guide/upgrade/support-lifecycle) are v32.xx, v31.xx, and v30.xx. For example: for the current (n) major release v32.xx, the supported n-1 and n-2 versions are v31.xx and v30.xx respectively.

You can upgrade the Prisma Cloud Console from a major release to the next major release, but not to a major release that follows the next. So, to upgrade from the v30.xx release to the v32.xx release, you will have to first upgrade to v31.xx and then upgrade to the v32.xx release.

## Enhancements

| FEATURE                        | DESCRIPTION                                                                                                                                                                                                                                                                                          |
| ------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **A new registry scan status** | A new status, **Partially Completed**, has been added to the scan statuses for registry scans. This status is assigned when at least one image has been successfully scanned in the registry. The Partially Completed status also displays the number of images that have been scanned successfully. |

## Intelligence Stream Updates

| **Feature**                                         | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| --------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Severity Mapping Update for Intelligence Stream** | <p>The severity values for the Intelligence stream are now mapped into 2 predefined values: “ High” and “Medium”.</p><p>Note: The severity values are already normalized to create rules. The current change is only specific to the severity reporting name change.</p><p>The following list defines the new vendor severity mapping:</p><ul><li><strong>Current Severity</strong>: Important</li><li><strong>New Severity</strong>: High</li><li><strong>Vendors</strong>: Amazon, Oracle, RedHat, Rocky, Suse, Ubuntu</li><li><strong>Current Severity</strong>: Moderate</li><li><strong>New Severity</strong>: Medium</li><li><strong>Vendors</strong>: Oracle, RedHat, Rocky, Suse, Windows</li><li><strong>Current Severity</strong>: End-of-life</li><li><strong>New Severity</strong>: Low, Medium, High, or Critical based on NVD</li><li><strong>Vendors</strong>: Debian</li></ul><p><strong>Note</strong>: End-of-life will be set in the vulnerability status.</p><p><strong>Note</strong>: The previous “unimportant”, “unassigned”, “untriaged”, “negligible” and “not yet assigned” severity mapping behaviour remains unchanged.</p><p>All the other unrecognized severity values from the different feeds will be assigned according to the NVD severity.</p><p>For more information, see <a href="https://docs.prismacloud.io/en/compute-edition/32/admin-guide/vulnerability-management/cvss-scoring#mappings">CVSS Scoring</a>.</p> |
| **End of support for Debian 10 (Buster)**           | <p>Debian 10 (Buster) reached end-of-life on June 30, 2024. Starting from July 2024, the Debian Long Term Support (LTS) team has stopped providing security information for Debian 10.</p><p>Consequently, vulnerabilities related to Debian 10 (Buster) were removed from the Prisma Cloud Intelligence Stream.</p><p><strong>Impact</strong>: Starting from this version, customers using Debian Buster (LTS or ELTS) will no longer see vulnerability data related to this version.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |

## API Changes and New APIs

There are no API changes for this release.

## Addressed Issues

| **WAAS Counters Periodically Stop Incrementing and Need Defender Restart**                                | The issue related to interruption in the communication between a defender and the console—​that was introduced by the newly introduced fail-safe mechanism aimed to prevent any impact to customer traffic or downtime—​is resolved. The fix requires you to upgrade the Console and the Defenders to version 33.00.                                                                                                                                                                      |
| --------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Reporting All Affected Versions for GO Package CVEs**                                                   | <p>For some GO package CVEs, Prisma Cloud did not completely report all the affected versions, particularly when multiple version ranges were involved, resulting in occasional false negatives.</p><p>This issue is fixed. Prisma Cloud now reports all the affected versions for GO package CVEs.</p>                                                                                                                                                                                   |
| **Improved CVE Matching for JAR Files with Group IDs**                                                    | <p>When a JAR file with a group ID is used as a dependency in other JAR files within the same image, Prisma Cloud might fail to properly identify or match CVEs to those JAR files.</p><p>This issue is resolved. Prisma Cloud now correctly handles group IDs in both the Defender and the Console, improving the ability to identify CVEs accurately for such JAR files.</p>                                                                                                            |
| **Fixed False Positives Caused by RPM and Third-Party Package Name Discrepancies**                        | Addressed the issue of false positives during vulnerability assessment due discrepancies between RPM package names, , and third-party package names where the same CVE may be listed under different names for example, `urllib3` for Python versus `python3-urllib3` for RPM. This inconsistency led to potential false positives or missed vulnerabilities. In order to validate if the third-party package should be reported, Prisma Cloud now also assesses the origin package name. |
| **Improved parsing of Jenkins Security Advisory for Fix Versions**                                        | Corrected parsing of Jenkins security information in affected versions and fix versions due to a scheme change. For example, the Jenkins Security Advisory 2021-10-06 did not produce fixed versions, showing all versions as vulnerable despite CVE-2014-3577 being fixed up to and including version 2.314.                                                                                                                                                                             |
| **Fixed incorrect Image Name Retrieval for Non-RPM Containers in Openshift Clusters**                     | Addressed an issue with Openshift cluster where incorrect image names were fetched for non RPM container images due to the cluster having a generic name for example, openshift-release-dev/ocp-v4.0-art-dev. To resolve this, the mapping extracts the release and version from image labels and adjusts the name by combining registry, origin name, release, and version to be the image name. For example `<registry>/<image_name>:<version>-<release>`.                              |
| **Support for FIPS-enabled OpenSSL packages**                                                             | <p>Previously, Prisma Cloud skipped scanning Federal Information Processing Standards (FIPS)-enabled OpenSSL packages to avoid overriding older releases, and instead matched against non-FIPS versions. This led to inaccurate vulnerability reporting.</p><p>This issue has been fixed. Prisma Cloud now fully supports scanning FIPS-enabled OpenSSL versions, ensuring correct vulnerability detection and eliminating false positives.</p>                                           |
| **Add collections filtering behavior**                                                                    | Previously, image scan filtering by collection restricted the collections listed in the Collections column to the collection selected in the filter. This issue is fixed now. Now, for each image, all related collections of the filtered images are displayed, even when a specific collection filter is applied.                                                                                                                                                                       |
| **Errors added to Console log when scanning images by Defender**                                          | <p>Previously, errors encountered during image scans by Defender were not added to the console log.</p><p>This issue has been fixed. Now, when Defender scans images, error messages are printed to the console log along with the image ID and the name of the Defender.</p>                                                                                                                                                                                                             |
| **\[Container dump API] Allow to include labels for each container**                                      | A new optional query parameter `includeLabels` is added to the [Download Container Scan Results](https://pan.dev/prisma-cloud/api/cwpp/get-containers-download/) API. This change will add all the labels corresponding to each container in the API response.                                                                                                                                                                                                                            |
| **Ruby Pessimistic version constraint rules are not merged correctly with other rule ranges causing FPs** | Previously, Prisma Cloud did not handle cases involving unaffected and patched Ruby version ranges correctly. Additionally, cases, where patched Ruby version ranges, were included within unaffected Ruby versions using the pessimistic version constraint (\~>), those cases were also not handled correctly. This issue has been resolved.                                                                                                                                            |

## Backward Compatibility for New Features

There is no backward compatibility for new features in this release.

## Changes in Existing Behavior

| FEATURE                                                | DESCRIPTION                                                                                                                                                                                                                                                                                                                                  |
| ------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Enhancement to Photon OS and Amazon Linux OS Feeds** | <p>Prisma Cloud now parses Photon OS and Amazon Linux OS feeds using CVE IDs as the primary vulnerability identifier instead of advisory IDs.</p><p>This change enhances Prisma Cloud’s ability to correlate third-party data, and use vendor-provided information, including backports, severity assessments, and vulnerability scores.</p> |

## End of Support Notifications

There are no End of Support notifications for this release.

## Deprecation Notices

There are no other deprecation notices for this release.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/ce-release-notes/32/prisma-tm-cloud-compute-edition-release-information/release-notes-32-07.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
