> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/ce-release-notes/33/prisma-tm-cloud-compute-edition-release-information/known-issues-33.md).

# Fixed and Known Issues in 33.xx

The following table lists the fixed issues for 33.xx releases.

## Fixed Issues

| **ISSUE ID**                                                                                               | **DESCRIPTION**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| ---------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>CWP-62576</strong></p><p><mark style="background-color:orange;">Fixed in 33.03.138</mark></p>   | <p><strong>Resolving Severity Scores and CVE Links for GO Vulnerabilities in OSV Feed</strong></p><p>When processing CVEs sourced from both the GO and GitHub Security Advisories (GHSA) formats in the Open Source Vulnerability (OSV) feed, incorrect severity scores and CVE links were assigned.</p><p>This issue is resolved. The fix ensures that the severity scores, CVSS values, and CVE links for GO vulnerabilities are accurate and aligned with the official OSV GO feed.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| <p><strong>PCSUP-26234</strong></p><p><mark style="background-color:orange;">Fixed in 33.03.138</mark></p> | <p><strong>Storage issues during the Defender shutdown process</strong></p><p>The Defender shutdown process in versions 32.02 through 32.05 (inclusive) shut down the storage component using a third-party package. This package used a flag to force storage to unmount during the shutdown, which lead to storage corruption in some cases. This issue was resolved in 32.06 by modifying the shutdown process to perform a non-forced unmount.</p><p>For any Defender instance from the affected versions that has already been shut down, upgrade the defender to a non-affected version (32.06 or later) and then reboot the node to clean up any storage corruption.</p>                                                                                                                                                                                                                                                                       |
| <p><strong>CWP-62313</strong></p><p><mark style="background-color:orange;">Fixed in 33.02.130</mark></p>   | <p><strong>Improved Status Filter for Cloud Security Agent Page</strong></p><p>The "Status" filter under <strong>Prisma UI > Manage > Defenders > Cloud Security Agent</strong> was displaying only the statuses present in the table, instead of all possible statuses.</p><p>This issue has been resolved. The CSA status filter now shows a list of all available statuses: Connected, Disconnected, and Lost. This ensures users can filter the table by any status.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| <p><strong>CWP-35710</strong></p><p><mark style="background-color:orange;">Fixed in 33.02.130</mark></p>   | <p><strong>Removing Namespaces After Resource Deletion</strong></p><p>In some cases, namespaces remained visible even after all resources within them had been deleted. This led to incorrect vulnerability assessments as the namespaces were not properly removed from the results. This issue is now resolved.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| <p><strong>CWP-62296</strong></p><p><mark style="background-color:orange;">Fixed in 33.02.130</mark></p>   | <p><strong>Consistent Vulnerability Data for Red Hat-Sourced Packages</strong></p><p>Certain vulnerabilities for Red Hat packages showed a Red Hat severity but CVSS scores from NVD.</p><p>This mismatch is now resolved. The fix ensures that both the severity and CVSS score now align with Red Hat’s data, eliminating inconsistencies.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| <p><strong>CWP-62084</strong></p><p><mark style="background-color:orange;">Fixed in 33.01.137</mark></p>   | <p><strong>Updating the list of binaries exposed to a vulnerability after rerunning a scan</strong></p><p>Rerunning a scan didn’t update the binary packages exposed to a vulnerability. This issue is fixed now.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| <p><strong>CWP-61947</strong></p><p><mark style="background-color:orange;">Fixed in 33.01.137</mark></p>   | <p><strong>Boot volume encryption in agentless scanning</strong></p><p>Fixed an issue with the agentless scanner boot volume default encryption.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| <p><strong>CWP-61606</strong></p><p><mark style="background-color:orange;">Fixed in 33.01.137</mark></p>   | <p><strong>CSV Export Compatibility with Excel</strong></p><p>The exported CSV file from the <strong>Monitor > Vulnerabilities > Images > Deployed</strong> page could not be opened in Excel when the Hosts field exceeded the maximum character limit of 32,768 per column.</p><p>This issue is resolved. The fix ensures that the CSV now lists all the hostnames running the same image. However, if the total length exceeds 32,757 characters, the list is truncated, and the number of truncated hostnames is indicated in the CSV.</p>                                                                                                                                                                                                                                                                                                                                                                                                        |
| <p><strong>CWP-59281</strong></p><p><mark style="background-color:orange;">Fixed in 33.01.137</mark></p>   | <p><strong>Improved vulnerability reporting for Debian images</strong></p><p>When scanning Debian images, Prisma Cloud occasionally missed some CVEs related to specific package versions. This issue is fixed.</p><p>The fix prioritizes CVE matches from the security repository and Prisma Cloud now reports all previously missing CVEs for packages in Debian images.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| <p><strong>CWP-58952</strong></p><p><mark style="background-color:orange;">Fixed in 33.01.137</mark></p>   | <p><strong>Improved vulnerability detection for multiple Python versions</strong></p><p>In previous versions of Defender, vulnerabilities were only detected and reported for a single Python installation on a host, even if multiple Python versions were installed. This resulted in False Negatives (FN), where vulnerabilities in other Python versions were missed.</p><p>The issue is fixed. Prisma Cloud will now scan and report vulnerabilities for each installed Python version on a host.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| <p><strong>CWP-59654</strong></p><p><mark style="background-color:orange;">Fixed in 33.01.137</mark></p>   | <p><strong>Support for Amazon Linux CVEs</strong></p><p>Previously, Prisma Cloud reported several false positive vulnerabilities for Amazon Linux CVEs that were marked as "not affected" by Amazon.</p><p>Prisma Cloud now fully supports CVEs classified as “not affected” by Amazon, improving the accuracy of vulnerability reporting for Amazon products and resolving the false positive issue. The supported Amazon Linux distributions include Amazon Linux, Amazon Linux 2, and Amazon Linux 2023.</p><p>Prisma Cloud does not support CVEs labeled as "pending fix" or "no fix planned," as Amazon does not provide the required package version details for precise CVE status reporting.</p>                                                                                                                                                                                                                                              |
| <p><strong>CWP-61444</strong></p><p><mark style="background-color:orange;">Fixed in 33.00.169</mark></p>   | <p><strong>Improvements in Amazon Linux Vulnerability Reporting</strong></p><p>Vulnerability information for many Amazon Linux CVEs lacked consistency across different Intelligence Stream updates, including changes in severity levels and fixed status versions. To address this, several key improvements were made, including enhanced consistency across scans, improved handling of duplicated CVEs, accurate ALAS to CVE conversion, and refined kernel package rules. These changes ensure more reliable and actionable vulnerability information for all Amazon distributions and kernel packages.</p>                                                                                                                                                                                                                                                                                                                                     |
| <p><strong>CWP-58814</strong></p><p><mark style="background-color:orange;">Fixed in 33.00.169</mark></p>   | <p><strong>Standardizing Java Versioning for Accurate Vulnerability Mapping</strong></p><p>Inconsistent version numbering for Java products led to several false positives in Prisma Cloud security scans. To ensure accurate mapping of vulnerabilities to Java versions, all Java product versions will be normalized to the standard 1.x format. For example, in the <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-21930">CVE-2023-21930</a> entry on the National Vulnerability Database (NVD), OpenJDK 8 will map to Java 1.8.</p>                                                                                                                                                                                                                                                                                                                                                                                                          |
| <p><strong>CWP-58355</strong></p><p><mark style="background-color:orange;">Fixed in 33.00.169</mark></p>   | <p><strong>Enhanced Detection for Minor Versions in Alpine Packages</strong></p><p>Alpine’s security database shows vulnerabilities for each Alpine package, including fixed versions and associated CVEs. However, when the CVE does not include a fixed version, the rule misses vulnerabilities in minor versions, leading to incomplete vulnerability coverage. This issue has been fixed. The updated vulnerability rules ensure that minor versions are included, even when no specific fixed version is available.</p>                                                                                                                                                                                                                                                                                                                                                                                                                         |
| <p><strong>CWP-61220</strong></p><p><mark style="background-color:orange;">Fixed in 33.00.169</mark></p>   | <p><strong>CVEs Resolved in Release 33.00</strong></p><p>While alerts were generated for CVE-2024-6104 and CVE-2024-29018, Prisma Cloud was not directly vulnerable and remained safe to use. The alerts have been resolved in Prisma Cloud release 33.00.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| <p><strong>CWP-58073</strong></p><p><mark style="background-color:orange;">Fixed in 33.00.169</mark></p>   | <p>Customers could pass invalid data to the <code>v1/alert-profile</code> and <code>collections</code> APIs. To address this issue, the following validations have been added:</p><ul><li><p>For <code>v1/alert-profiles</code> APIs:</p><ul><li>The name parameter must be less than 50 characters.</li><li>The email address must be valid.</li><li>The port parameter must not be less than 1.</li><li>The recipient’s email address must be valid.</li></ul></li><li><p>For <code>Collections</code>:</p><ul><li>The name parameter must be less than 50 characters.</li><li>The description parameter must be less than 200 characters.</li></ul></li></ul>                                                                                                                                                                                                                                                                                      |
| <p><strong>CWP-59190</strong></p><p><mark style="background-color:orange;">Fixed in 33.00.169</mark></p>   | <p><strong>Improved Image Scanning</strong></p><p>If the Defender disconnects while scanning an image that has the same tag, registry, repository, and credentials, it can lead to multiple scan requests of the same image. In addition, a race condition could sometimes prevent the image from being properly removed from the host container registry after scanning. This fix ensures that only one scan is performed per image, even if multiple scan requests are triggered by disconnections. This reduces the load on the Defender.</p><p>The fix also addresses the race condition. However, not all possible race conditions are addressed:</p><ul><li>If the same image is scanned in different repositories or registries, race conditions are not addressed by this fix.</li><li>If the same image is scanned in the same repository and registry but with different tags, the fix does not handle potential race conditions.</li></ul> |
| <p><strong>CWP-59443</strong></p><p><mark style="background-color:orange;">Fixed in 33.00.169</mark></p>   | Previously, users experienced intermittent timeouts in a shorter timeframe than the default inactivity period, which was set to 300 minutes under **Settings > Enterprise Settings > User Idle Timeout > CX**. This issue has now been resolved, and all Prisma Cloud tabs log out only after 300 minutes of inactivity.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| <p><strong>CWP-59841</strong></p><p><mark style="background-color:orange;">Fixed in 33.00.169</mark></p>   | <p><strong>Agentless Scanning - Support for OCI root compartment scans</strong></p><p>OCI instances deployed in the root compartment were not scanned during Agentless scans. Instances in child compartments were scanned as expected, but root compartment instances were excluded without error. This issue is fixed-all compartments, including the root, are now scanned successfully.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| <p><strong>CWP-60298</strong></p><p><mark style="background-color:orange;">Fixed in 33.00.169</mark></p>   | <p><strong>Compliance IDs 440/441 in Lamba Scans</strong></p><p>Compliance IDs 440/441 triggered false positives during a serverless Lambda scan for kms permissions. This issue is fixed.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| <p><strong>CWP-60356</strong></p><p><mark style="background-color:orange;">Fixed in 33.00.169</mark></p>   | <p><strong>Improved Clarity in Incident Log Messages</strong></p><p>In certain cases, the command that triggered an incident was missing from the incident capture flow. This caused the messages in the Incident Explorer to occasionally lack clarity, leading to incomplete logs. The fix ensures that executed commands are now included in audit reports when available. Additionally, it prevents the generation of incomplete reports if the command is missing</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| <p><strong>CWP-60819</strong></p><p><mark style="background-color:orange;">Fixed in 33.00.169</mark></p>   | <p><strong>Reduced Registry Scan Duration</strong></p><p>Prisma Cloud sometimes experienced extended registry scan times due to certain images not being correctly recognized. This led to the registry scan missing cached images, resulting in longer scan durations. The cache miss happened because the image ID hash from the Container Runtime API was missing the sha256 prefix. The issue has now been fixed by using the hash from the registry scan request sent by the Console, when available. This ensures cache hits and enhances scan performance.</p>                                                                                                                                                                                                                                                                                                                                                                                 |
| <p><strong>CWP-60900</strong></p><p><mark style="background-color:orange;">Fixed in 33.00.169</mark></p>   | Exporting discovered APIs to OpenAPI CSV files from the **Runtime > Monitor > WAAS > API discovery > Export CSV** page failed if the API had unsupported methods such as PURGE. This issue is fixed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| <p><strong>CWP-61291</strong></p><p><mark style="background-color:orange;">Fixed in 33.00.169</mark></p>   | Previously, a "buffer full" error was reported with an HTTP 500 status code, when the same port was reused in a specific order across multiple apps in a single WAAS rule. This issue is fixed now.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| <p><strong>CWP-61362</strong></p><p><mark style="background-color:orange;">Fixed in 33.00.169</mark></p>   | Fixed an issue where compliance alerts for malware (Compliance ID 455) did not appear in daily email reports despite failed resources being detected. This fix ensures accurate reporting for agentless scans.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| <p><strong>CWP-61375</strong></p><p><mark style="background-color:orange;">Fixed in 33.00.169</mark></p>   | <p><strong>Agentless Scanning - Resource Group Creation in Target Azure Account during Hub Scan Mode</strong></p><p>Fixed an issue where resource groups were created in the target account during Azure agentless Hub scan mode. Now, resource groups are no longer created in the target account when a hub account is defined on it.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| <p><strong>CWP-61752</strong></p><p><mark style="background-color:orange;">Fixed in 33.00.169</mark></p>   | The issue related to interruption in the communication between a defender and the console—​that was introduced by the newly introduced fail-safe mechanism aimed to prevent any impact to customer traffic or downtime—​is resolved. The fix requires you to upgrade the Console and the Defenders to version 33.00.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |

## Known Issues

The following table lists the known issues for 33.00 release.

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>ISSUE ID</strong></td><td><strong>DESCRIPTION</strong></td></tr><tr><td><strong>CWP-62780</strong></td><td><p>When deploying a Fargate Defender alongside an Nginx server, the Nginx server was inaccessible through a browser, despite both the Fargate Defender container and the Nginx server container launching successfully. Additionally, no access logs were generated in the CloudWatch log file.</p><p><strong>Workaround</strong>: Customize the Nginx container’s error logging behavior by performing the following steps.</p><pre><code>#1: Edit the nginx.conf as below.
# Make sure that this file is copied from the official Nginx container, and not newly created.
=
error_log stderr;
=
#2: Use the above custom nginx.conf and the following Dockerfile to build a new Docker image.
=
# Use the official Nginx image as the base
FROM nginx:latest
# Remove existing symlink for error.log if it exists
RUN rm -f /var/log/nginx/error.log
# Copy custom nginx.conf into the container
COPY nginx.conf /etc/nginx/nginx.conf
# Start Nginx
CMD ["nginx", "-g", "daemon off;"]
=
</code></pre></td></tr><tr><td><strong>CWP-59515</strong></td><td><p><strong>K8s Defender Crash Loop on RKE2</strong></p><p>The K8s defender pods on the RKE2 go into a crash loop if the defender is deployed using the default YAML file options.</p><p><strong>Workaround</strong>: For Kubernetes defenders on RKE2, create the YAML file with the “SELinux Policy” option. This workaround is applicable to RKE2 only.</p></td></tr><tr><td><strong>CWP-62297</strong></td><td><p><strong>Twistlock console unable to list image tags from remote repo</strong></p><p>If defender and remote repository are in different subnet, the image tag pulling using <code>podman search --list -tags</code> is not supported with the same access token issued by registry.twistlock.com.</p></td></tr><tr><td><strong>CWP-59435</strong></td><td><p><strong>Enabling FIPS with TLS 1.3 does not work for WAAS In-Line</strong></p><p>Due to a compatibility issue in Go programming language’s package, the HTTP server is unable to operate with both FIPS mode and TLS 1.3 enabled simultaneously. This limitation is preventing WAAS In-Line from supporting the configuration.</p></td></tr><tr><td><strong>CWP-53375</strong></td><td><p>In <strong>Inventory > Compute Workloads</strong>, for users logged in with a role other than the built-in system admin role, currently only data about cloud provider managed registry images and VM instances can be viewed.</p><p>In particular, for such roles currently data about the following types of assets is not displayed:</p><ul><li>Run stage images</li><li>Private registry images</li><li>Build stage images</li><li>On-premises hosts/hosts managed by cloud providers unsupported by Compute</li></ul></td></tr><tr><td><strong>CWP-58896</strong></td><td><p><strong>ACI Cloud Discovery- Incorrect Status Field Mapping and Defend Functionality Gaps</strong></p><p>With the support for ACI in cloud discovery, here are the two issues:</p><ul><li>Status: The <code>status</code> field currently utilizes Properties > ProvisioningState, which does not reflect the container status. For more information, refer to <a href="https://learn.microsoft.com/en-us/azure/container-instances/container-state">Azure Container Instances states</a>.</li><li>Defend: The Defend functionality does not support Azure Container Instances (ACI). The Defend is enabled across all accounts and services, and when selected, it redirects to Images > Registry Settings.</li></ul></td></tr><tr><td><strong>CWP-58709</strong></td><td><p><strong>Duplicate Admission Rules</strong></p><p>Six admission rules released in Version 32, Update 2 were found to be duplicates of older existing rules. If you need the functionality provided by these rules, we recommend disabling the old rules and using the new corresponding rules, as the older rules will be removed in an upcoming release.</p><p>The old rules and their corresponding new rules are as follows:</p><ul><li><strong>Old rule</strong>: Twistlock Labs - CIS - Pod created in host process ID namespace. <strong>New rule</strong>: Twistlock Labs - PSS - Baseline - Pod with containers that share host process ID (hostPID) namespace</li><li><strong>Old rule</strong>: Twistlock Labs - CIS - Pod created on host IPC namespace. <strong>New rule</strong>: Twistlock Labs - PSS - Baseline - Pod with containers that share host IPC namespace</li><li><strong>Old rule</strong>: Twistlock Labs - CIS - Pod created on host network. <strong>New rule</strong>: Twistlock Labs - PSS - Baseline - Pod that allows containers to share the host network namespace</li><li><strong>Old rule</strong>: Twistlock Labs - Pod created with sensitive host file system mount. <strong>New rule</strong>: Twistlock Labs - PSS - Baseline - Pod created with sensitive host file system mount</li><li><strong>Old rule</strong>: Twistlock Labs - CIS - Privileged pod created. <strong>New rule</strong>: Twistlock Labs - PSS - Baseline - Pod should not run privileged containers</li><li><strong>Old rule</strong>: Twistlock Labs - CIS - Privilege escalation pod created. <strong>New rule</strong>: Twistlock Labs - PSS - Restricted - Pod that allows container privilege escalation</li></ul><p>Even though both the new and old rules are enabled by default, you will not receive duplicate alerts as only the first encountered rule is enforced.</p></td></tr><tr><td><strong>CWP-58350</strong></td><td><p><strong>CVE Exclusions Update</strong></p><p>The following CVEs that are included in the Intelligence Stream feed are ignored:</p><ul><li><a href="https://github.com/advisories/GHSA-xm99-6pv5-q363">CVE-2022-29583 - GitHub Advisory Database</a> as it is a disputed vulnerability.</li><li><a href="https://github.com/cri-o/cri-o/security/advisories/GHSA-2cgq-h8xw-2v5j">CVE-2024-3154 - Arbitrary Systemd Property Injection</a> as Defender does not directly use this package.</li></ul></td></tr><tr><td><strong>CWP-52710</strong></td><td>While upgrading consoles from the 30.03 release to a 32.xx release, the error log <code>failed to retrieve "size" specification option value</code> during the migration doesn’t impact the migration process and can be ignored.</td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/ce-release-notes/33/prisma-tm-cloud-compute-edition-release-information/known-issues-33.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
