> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-known-issues/known-fixed-issues.md).

# Known and Fixed Issues on Prisma Cloud

The following table lists the known and fixed issues on Prisma Cloud.

The list of fixed issues are not cumulative; only the issues that are fixed with the last published release are included here.

* [Known Issues](#known-issues)
* [Fixed Issues](#fixed-issues)

## Known Issues

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>ISSUE ID</strong></td><td><strong>DESCRIPTION</strong></td></tr><tr><td><p><strong>Azure Permission Deprecation</strong></p><p><mark style="background-color:orange;">26.4.1</mark></p></td><td><p>Azure has deprecated the following permissions required to ingest resources. These permissions will be removed as a requirement in a future release.</p><ul><li><code>Microsoft.ClassicCompute/VirtualMachines/read</code></li><li><code>Microsoft.ClassicCompute/domainNames/read</code></li><li><code>Microsoft.ClassicStorage/StorageAccounts/read</code></li><li><code>Microsoft.ClassicNetwork/networkSecurityGroups/read</code></li><li><code>Microsoft.ClassicNetwork/virtualNetworks/read</code></li><li><code>Microsoft.ClassicNetwork/reservedIps/read</code></li></ul><p>As a workaround, you can remove these permissions from your custom role and run Terraform to update your Azure cloud account configuration.</p></td></tr><tr><td><p><strong>AWS UAE and Bahrain Assets</strong></p><p><mark style="background-color:orange;">26.4.1</mark></p></td><td>Prisma Cloud supports asset ingestion and alerting for assets deployed in AWS UAE and Bahrain. Due to ongoing AWS issues, we have temporarily disabled discovery of configuration assets in these regions.</td></tr><tr><td><p><strong>Azure Permission Removal</strong></p><p><mark style="background-color:orange;">26.2.1</mark></p></td><td><p>Azure has deprecated the following permission required to ingest resources. This permission will be removed as a requirement in a future release.</p><ul><li><code>Microsoft.Orbital/spacecrafts/read</code></li></ul></td></tr><tr><td><p><strong>Ingested Findings Sources</strong></p><p><mark style="background-color:orange;">25.12.1</mark></p></td><td>If Prisma Cloud Compute is enabled on a specific resource or account and you have configured it to ingest data from third party sources such as Tenable, Qualys or AWS inspector, Prisma will only list findings from Compute and not from third party sources for that particular resource.</td></tr><tr><td><p><strong>Flow Logs Ingestion Limitation</strong></p><p><mark style="background-color:orange;">25.12.1</mark></p></td><td>MDC configuration ingestion does <strong>not</strong> currently ingest metadata from <strong>Azure Virtual Machine Scale Set</strong> that are required for Flow Logs decoration (VPC identification). As a result, you cannot run RQL queries using the <strong>Virtual Network</strong> filter when the traffic is generated by an <strong>Azure Virtual Machine Scale Set</strong>. You can still run queries using other filters, such as <strong>Source IP</strong> and <strong>Destination IP</strong>.</td></tr><tr><td><p><strong>Vulnerability data for Windows hosts</strong></p><p><mark style="background-color:orange;">34.02.133</mark></p></td><td><p><strong>Vulnerability Data Access Issue in Prisma Cloud Enterprise Edition (Windows CSA only)</strong></p><p><strong>Issue</strong></p><p>Users of Prisma Cloud Enterprise Edition are currently experiencing an issue preventing access to vulnerability details detected by cloud security agents (CSA) on Windows hosts. This data is inaccessible through both the user interface and the API.</p><p><strong>Clarification</strong></p><p>It is important to note that this issue solely affects the access to vulnerability data. Cloud security agents are successfully detecting and reporting vulnerabilities, and the underlying data remains intact. All historical and newly detected vulnerability data will become available once this access issue is resolved.</p><p><strong>Resolution Timeline</strong></p><p>Palo Alto Networks is actively working on a fix for this critical issue. Please monitor official communication channels for updates regarding the fix’s availability and implementation steps.</p></td></tr><tr><td><p><strong>RLP-156679</strong></p><p><mark style="background-color:orange;">25.8.1</mark></p></td><td><p><strong>Issues Found Warning during Onboard or Update</strong></p><p>You may encounter an <strong>Issues Found Warning</strong> under <strong>Security Capabilities and Permissions > Misconfigurations > Asset</strong> configuration when onboarding or updating your AWS cloud accounts. This warning lists the required permissions for various API services.</p><p>You can safely ignore this warning message. It is trigerred by the <code>backup:ListRecoveryPointsByBackupVault</code> permission for the <code>aws-backup-recovery-point</code> API. The API is disabled by default.</p></td></tr><tr><td><p><strong>Host details display incorrect Windows version</strong></p><p><mark style="background-color:orange;">34.01.126</mark></p></td><td>Windows Server 2025 is incorrectly reported as Windows Server 2022 on the Host details panel.</td></tr><tr><td><strong>PCSUP-28459</strong></td><td>The total count of alerts detected may sometimes increase even if assets in your tenant are not updated. Transient changes with CSP APIs, may sometimes lead to this intermittent issue.</td></tr><tr><td><strong>PCSUP-27662</strong></td><td>Prisma Cloud Application Security <strong>Home > Projects > Repositories</strong> has a known limitation where, selecting <strong>Repositories All</strong> when generating a CSV scan report does not generate a report with a full list of all available repositories. Results are limited to a maximum of 500.</td></tr><tr><td><strong>RLP-155997</strong></td><td><p>When entering an RQL query, if the specified conditions are met for the <code>aws-kms-get-key-rotation-status</code> API, rotation and policy data (specifically in the fields <code>keyRotations</code> and <code>keyPolicies</code> in the config JSON) will not be ingested. The conditions include:</p><ul><li><code>KeyMetadata.Origin</code> being one of ('EXTERNAL', 'AWS_CLOUDHSM')</li><li><code>KeyMetadata.KeyManager</code> being <code>AWS</code></li><li><code>KeyMetadata.Description</code> starting with <code>Default master</code></li></ul><p>As a result of these conditions, the list of related assets for <code>aws-kms-get-key-rotation-status</code> API will not be visible.</p></td></tr><tr><td><strong>RLP-155983</strong></td><td><p>Prisma Cloud uses EventBridge keys to authenticate events in the webhook, and these keys do not support key rotation. If you receive alerts for these keys 365 days after their setup due to the violation of 'AWS Secrets Manager - Ensure unmanaged secrets are rotated at least every 365 days' policy, you will not be able to resolve these alerts by rotating the keys.</p><p><strong>Resolution</strong>— Alerts must be manually dismissed for each account. You can also perform bulk dismissal to resolve these alerts.</p></td></tr><tr><td><strong>--</strong></td><td><p><strong>Google Cloud Run Functions (Gen2) May Not Be Scanned with Selective Registry Scanning</strong></p><p>Google offers serverless functions in two versions: Cloud Functions ("Gen1") and Cloud Run Functions ("Gen2"). Prisma Cloud fully supports vulnerability scanning for Gen1 functions.</p><p>For Gen2, when code is uploaded to Google Cloud Run Functions, a container image is created and stored in Google Artifact Registry (GAR) or Google Container Registry (GCR). If Prisma Cloud is set to scan all registries in your GCP account, Gen2 function images will be scanned. To view results, check the relevant registry and refer to Google’s naming conventions for container images <a href="https://cloud.google.com/artifact-registry/docs/docker/names">here</a>.</p><p>If Prisma Cloud is configured to scan only selected repositories, the specific repository used by Cloud Run might not be scanned. We are working to support Gen2 function scanning in this scenario.</p></td></tr><tr><td><strong>CWP-62339</strong></td><td><p><strong>Discrepancies in Vulnerability Scan Results</strong></p><p>In rare instances, discrepancies were observed between vulnerability scan results from Defender and <code>twistcli</code> host scans.</p><p>For example, certain compliance checks identified by <code>twistcli</code> were not reflected in Defender scan results, and vice versa. Additionally, for some operating systems, <code>twistcli</code> reported a higher number of high-severity findings compared to Defender.</p></td></tr><tr><td><strong>—</strong></td><td><p>Even though non-System Administrators do not have the permission required to activate subscriptions, the <strong>Subscribe</strong> button is displayed for various modules under <strong>Subscriptions</strong>.</p><p><strong>Resolution</strong>—There is no impact on system behavior since Prisma Cloud runs a check, which prevents non-System Administrators from activating the subscription even if they click <strong>Subscribe</strong>.</p></td></tr><tr><td><strong>RLP-155193</strong></td><td><p>Prisma Cloud only ingests resources for the <strong>Google Vertex AI AIPlatform API</strong> (<strong>gcloud-vertex-ai-aiplatform-index</strong>) API in the following regions where the service is available according to the <a href="https://cloud.google.com/vertex-ai/docs/general/locations#feature-availability">Cloud Service Provider</a>.</p><ul><li>asia-east1</li><li>asia-east2</li><li>asia-northeast1</li><li>asia-northeast3</li><li>asia-south1</li><li>asia-southeast1</li><li>asia-southeast2</li><li>australia-southeast1</li><li>europe-central2</li><li>europe-west1</li><li>europe-west2</li><li>europe-west3</li><li>europe-west4</li><li>europe-west6</li><li>europe-west9</li><li>me-west1</li><li>northamerica-northeast1</li><li>northamerica-northeast2</li><li>southamerica-east1</li><li>us-central1</li><li>us-east1</li><li>us-east4</li><li>us-south1</li><li>us-west1</li><li>us-west2</li><li>us-west3</li><li>us-west4</li></ul><p><strong>Impact</strong>— You may encounter the <code>Matching Engine is not supported</code> error in regions that are not used or where the API service is not supported.</p></td></tr><tr><td><strong>RLP-154164</strong></td><td>With 24.11.1 release, we updated rule metadata for config policies in the backend. This updated the last modified date of custom policies too. As a result you may see a recent <code>Last Modified date</code> for some custom config policies, even if no changes were made. This does not have any impact on the policy evaluation and does not change the functional behaviour of the policies.</td></tr><tr><td><strong>CWP-59515</strong></td><td><p><strong>K8s Defender Crash Loop on RKE2</strong></p><p>The K8s defender pods on the RKE2 go into a crash loop if the defender is deployed using the default YAML file options.</p><p><strong>Workaround</strong>: For Kubernetes defenders on RKE2, create the YAML file with the “SELinux Policy” option. This workaround is applicable to RKE2 only.</p></td></tr><tr><td><strong>RLP-152525</strong></td><td>The resource URL on the <strong>Alerts Overview</strong> page is generated by evaluating the resource metadata present in the alert. In some cases, some of the resource metadata is not available to Prisma Cloud and hence the generated URL may be incorrect.</td></tr><tr><td><strong>RLP-153383</strong></td><td><p>Prisma Cloud does not support the ingestion of GCP Storage buckets with the <code>locationType</code> <code>Dual-region</code>.</p><p><strong>Impact</strong>: You may notice a mismatch between GCP Storage Bucket counts and the total number of GCP Storage Buckets listed in your GCP Project on Prisma Cloud.</p></td></tr><tr><td><strong>RLP-153057</strong></td><td>To provide enhanced performance, the <strong>Compliance</strong>/<strong>Asset Inventory</strong> trendline has been disabled for some tenants.</td></tr><tr><td><strong>RLP-150999</strong></td><td><p>Cloud resources located in disabled regions may trigger policy violations, resulting in false positive alerts. You may notice these misleading alerts associated with specific OOTB policies.</p><p><strong>Workaround</strong>: You must manually dismiss these false positive alerts.</p></td></tr><tr><td><strong>RLP-151696</strong></td><td><p>Some invalid assets related to accounts for which the cloud scan was not completed will be deleted.</p><p><strong>Impact</strong>: Open alerts on such existing invalid assets, where asset type is <code>Account Aggregate Entity</code> will get resolved.</p></td></tr><tr><td><strong>RLP-152263</strong></td><td><p>In certain cases, a system processing issue is causing deviations in the total, passed, and failed assets count.</p><p><strong>Impact</strong>: Inaccurate overall asset counts will be displayed on <strong>Asset Inventory</strong> and <strong>Compliance Dashboard</strong> for some customers.</p></td></tr><tr><td><strong>RLP-149425</strong></td><td><p>To ingest the <code>gcloud-cloud-domains-registration</code> API, you need the Viewer role or any least permissive built in roles such as Cloud Domains Viewer or Cloud Domains Admin, which includes the permissions <code>domains.registrations.list</code> and <code>domains.registrations.getIamPolicy</code>.</p><p>Custom roles cannot be configured to include these permissions, as Google Cloud Platform (GCP) does not permit it. As a result, Prisma Cloud will be unable to ingest the <code>gcloud-cloud-domains-registration</code> API when using a custom role.</p><p><strong>Impact</strong>: If the Viewer role or domain related built in role is correctly configured, ingestion of the <code>gcloud-cloud-domains-registration</code> API will proceed as expected.</p><p>If the Viewer role or domain related built in role is not configured, the API ingestion will fail, and <code>'Missing Permissions'</code> warning for the above permissions will not be displayed on the account status page.</p></td></tr><tr><td><strong>RLP-146718</strong></td><td>In UEBA, the <strong>Excessive Login Failures</strong> policy is impacted by the use of multithreading for processing audit log events. Due to splitting of events, in rare occurrences there is a possibility that an incident (false negative) may not be detected.</td></tr><tr><td><strong>RLP-143404</strong></td><td>On some Prisma Cloud stacks, the state of a few alerts generated for <strong>Attack Path</strong> policies was displayed as Open instead of Resolved. This was caused due to an issue, which is now fixed. However, currently the impacted alerts do not display the correct state.</td></tr><tr><td><strong>RLP-128421</strong></td><td><p>When you filter assets associated with the <strong>Azure AD B2C tenants</strong> in the Europe region, you may notice that assets listed on the <strong>Inventory</strong> page under <strong>Region ID</strong> and <strong>Region</strong> columns incorrectly display as GCP Europe instead of Azure Europe. However, you can safely assume that the assets listed under the <strong>Region</strong> and <strong>Region ID</strong> columns are Azure Europe instead of GCP Europe.</p><p><strong>Workaround</strong>: To verify the correct region, search for the <code>location</code> field in the asset’s JSON.</p></td></tr><tr><td><strong>RLP-133698</strong></td><td>If an Azure account being scanned is of account type Tenant, then Prisma cloud excludes AZURE_MONITOR_ACTIVITY_LOG_ALERT, AZURE_MONITOR_LOG_PROFILE, and ACCOUNT_AGGREGATE_ENTITY asset types from the scan.</td></tr><tr><td><strong>RLP-129856</strong></td><td><p>While testing integrations with third-party tools such as Jira, Webhook, Splunk, and Microsoft Teams in Prisma Cloud, "Unsecure url protocol" error may be displayed.</p><p><strong>Workaround</strong>: Update all URLs used during the setup process from <strong>HTTP</strong> to <strong>HTTPS</strong> to resolve the error. This update ensures a more secure connection without impacting your existing alert notifications.</p><p>If you do not want to update the URLs from HTTP to HTTPS, you can choose to ignore the error. This will not have any impact on your existing alert notifications.</p></td></tr><tr><td><strong>RLP-132750</strong></td><td><p>The following errors may occur when you onboard your OCI tenant to Prisma Cloud:</p><ul><li><strong>Either tenant ocid or user ocid or home region is incorrect or insufficient permissions.</strong></li><li><strong>Authentication Failed. Check Account Details.</strong></li></ul><p>You can safely ignore these errors. They occur due to the migration of OCI tenants from Oracle Identity Domains (IDCS) to the new OCI IAM on the OCI cloud services, resulting in a significant delay in activating the user API Keys used for OCI Cloud Account Onboarding.</p><p>To verify successful onboarding, go to <strong>Settings > Providers > Cloud Accounts</strong> and ensure your account <strong>Status</strong> is <strong>green</strong> after 24 hours.</p></td></tr><tr><td><strong>RLP-123335</strong></td><td>When configuring Jira fields in the Prisma Cloud Notification template, it is important to note that the automatic population is limited to fields specifically of types <code>user</code> and <code>labels</code>. Other field types may not be populated as expected during the setup process. This is a known issue.</td></tr><tr><td><strong>RLP-104295</strong></td><td>Prisma Cloud has fully adopted Microsoft Authentication Library (MSAL) for monitoring Azure instances. However, in very rare cases, you might come across log entries for calls from Prisma Cloud to Active Directory Authentication Library (ADAL) endpoints. These entries can be disregarded. A fix will be implemented to resolve these erroneous entries.</td></tr><tr><td><strong>RLP-90184</strong></td><td>The behavior of filters on the <strong>Alerts Overview</strong> page is slightly different from that on the <strong>Asset Inventory</strong> and <strong>Asset Explorer</strong> pages. On the <strong>Alerts Overview</strong> page when you select the <code>Asset Class</code>, <code>Resource Type</code>, and <code>Service Name</code> filters, the alerts displayed are a combination of those three selected filters. Whereas on the <strong>Asset Inventory</strong> and <strong>Asset Explorer</strong> pages, the preference is given to <code>Resource Type</code> over <code>Service Name</code> when both those filters are selected due to which the assets for which alerts are displayed on the <strong>Asset Inventory</strong> and <strong>Asset Explorer</strong> pages do not match those displayed on the <strong>Alerts Overview</strong> page.</td></tr><tr><td><strong>RLP-78777</strong></td><td><p>The AWS Global Accelerator service returns an Access Denied error with the error assumed-role/PrismaCloudReadOnlyRole/redlock is not authorized to perform: iam:CreateServiceLinkedRole on resource. The issue occurs because the <code>aws-global-accelerator-accelerator`</code> API requires you to enable the service-linked IAM role to ingest metadata. To resolve the error, add the role to include the required permissions.</p><p><strong>Workaround</strong>: If you do not want to enable the service-linked role, create a support ticket with Palo Alto Networks Technical Support to disable the AWS Global Accelerator service API.</p></td></tr><tr><td><strong>RLP-73807</strong></td><td>In Unified Asset Inventory, Compute alerts are not displayed in the Resource Explorer audit trail.</td></tr><tr><td><strong>RLP-75376</strong></td><td><strong>PCDS Azure only—</strong> If you have enabled public access from selected IP addresses on storage account with Prisma Cloud NAT IPs and Azure outbound IPs added to the allow list, ingestion fails with 403 error (permission denied).</td></tr><tr><td><strong>RLP-65612</strong></td><td><strong>PCDS Azure only—</strong> The <strong>Inventory</strong> page may display 400 error if data is not available.</td></tr><tr><td><strong>RLP-65602</strong></td><td><strong>PCDS Azure only—</strong> During onboarding when you enter the <strong>Client ID</strong> and <strong>Secret</strong>, if the Secret exceeds the specified length, a bad request error displays.</td></tr><tr><td><strong>RLP-68751</strong></td><td>In Unified Asset Inventory, only System Administrators can view the Compute assets and not other users. Compute alerts will not be accessible on Alerts pages for all users except System Administrators.</td></tr><tr><td><strong>RLP-65286</strong></td><td><p>When integrating Prisma Cloud with Jira, if the Jira <code>issueType</code> field uses space as a separator between the words, such as <code>Service Request</code> or <code>New Feature</code> , a 500 Internal Server error occurs while configuring Typeahead fields such as Reporter or Assignee, in a Notification Template. You will be unable to create a Notification Template for Jira with the Typeahead fields.</p><p><strong>Workaround</strong>: Rename the field to remove the space or add an underscore. For example, <code>ServiceRequest</code> or <code>New_Feature</code>. You can then add Typeahead fields in a Notification Template.</p></td></tr><tr><td><strong>RLP-65216</strong></td><td>If you have configured multiple flow logs for a VPC and if any of the flow logs are incorrectly configured, the flow log status on Prisma Cloud is reported as a warning (Amber). This status does not impact ingestion for all the correctly configured flow logs.</td></tr><tr><td><strong>RLP-62558</strong></td><td>The resource name displayed on the Alerts L2 page does not match the name displayed for the same resource on the Asset Explorer page.</td></tr><tr><td><strong>RLP-60005</strong></td><td>Prisma Cloud may not process some of the delete bucket events, due to which the buckets that you have deleted in the AWS console will be visible in the Prisma Cloud <strong>Inventory</strong> page.</td></tr><tr><td><strong>RLP-55036</strong></td><td>When changing the <strong>Maximum time before access keys expire</strong> value for access keys, it may take up to 15 minutes for the updates to take effect.</td></tr><tr><td><strong>RLP-40248</strong></td><td>When you create an alert rule and specify target resource tags, Prisma Cloud processes only a single resource tag key/value pair properly. Proper processing of multiple resource tags or resource tags with multiple values is not guaranteed. This behavior exists whether you create the alert rule through the Prisma Cloud console or through the CSPM API.</td></tr><tr><td><strong>RLP-27427</strong></td><td><p><strong>Applies to Prisma Cloud Data Security only</strong></p><p>Malware report is not available in PDF format.</p></td></tr><tr><td><strong>RLP-25117</strong></td><td><strong>Applies to Prisma Cloud Data Security only</strong> The Dashboard displays an error when you select an account group that does not contain any accounts.</td></tr><tr><td><strong>RLP-19480</strong></td><td>The Business Unit Report does not support multi-byte characters used in languages such as Japanese.</td></tr><tr><td><strong>RLP-19470</strong></td><td>The Business Unit Report csv file lists all enabled policies even when there are no open alerts, because there are no resources to scan.</td></tr><tr><td><strong>RLP-14469</strong></td><td><p>When you enable Dataflow compression for a cloud account, the subnetwork creation status may display a failure message on the onboarding status page. This error displays because the time threshold to create the subnetwork and report completion exceeds the response time threshold on Prisma Cloud.</p><p><strong>Workaround—</strong> Click to the previous page and click next to load the status page again.</p></td></tr><tr><td><strong>RLP-13485</strong></td><td>If you have the maximum number of VPCs (5) already created in the project and you then enable flowlog compression, the onboarding fails because Prisma Cloud is unable to add the network needed to enable Dataflow compression. When this happens the remediation steps in the message that displays is incorrect.</td></tr><tr><td><strong>RLP-9723</strong></td><td>The integration status check for Jira displays as yellow instead of red even if the integration is misconfigured.</td></tr><tr><td><strong>—</strong></td><td>Dashboard widgets don’t load for a large data set where the time window is also large.</td></tr><tr><td><strong>—</strong></td><td>The <code>aws-ecs-describe-task-definition</code> and <code>aws-emr-describe-cluster</code> APIs now run once every 24 hours to generate alerts. If you have cloud accounts with a significant amount of ECS/EMR resources, the resource status is updated once a day.</td></tr><tr><td><strong>—</strong></td><td>The configuration build policies are displayed even if you have not enabled Code Security module.</td></tr><tr><td><strong>—</strong></td><td>Currently when you edit default policies in the Code Security module, the policy is duplicated with the updated metadata. Both the unedited policy and the edited policy are then visible on <strong>Projects</strong> when the <strong>Status- Suppressed</strong> (for the original policy) and <strong>Errors</strong> (for the edited policy) are enabled.</td></tr><tr><td><strong>—</strong></td><td><p>AWS CloudTrail in the Osaka region (ap-northeast-3) do not display on the Prisma Cloud administrative console.</p><p>This issue requires a fix on AWS. When fixed on AWS, the issue will be automatically resolved on Prisma Cloud.</p></td></tr><tr><td><strong>CWP-62780</strong></td><td><p>When deploying a Fargate Defender alongside an Nginx server, the Nginx server was inaccessible through a browser, despite both the Fargate Defender container and the Nginx server container launching successfully. Additionally, no access logs were generated in the CloudWatch log file.</p><p><strong>Workaround</strong>: Customize the Nginx container’s error logging behavior by performing the following steps.</p><pre><code>#1: Edit the nginx.conf as below.
# Make sure that this file is copied from the official Nginx container, and not newly created.
=
error_log stderr;
=
#2: Use the above custom nginx.conf and the following Dockerfile to build a new Docker image.
=
# Use the official Nginx image as the base
FROM nginx:latest
# Remove existing symlink for error.log if it exists
RUN rm -f /var/log/nginx/error.log
# Copy custom nginx.conf into the container
COPY nginx.conf /etc/nginx/nginx.conf
# Start Nginx
CMD ["nginx", "-g", "daemon off;"]
=
</code></pre></td></tr><tr><td><strong>PCSUP-23081</strong></td><td>Due to a compatibility issue in Go programming language’s package, the HTTP server is unable to operate with both FIPS mode and TLS 1.3 enabled simultaneously. This limitation is preventing WAAS In-Line from supporting the configuration.</td></tr><tr><td><strong>—</strong></td><td>In 31.02.133, the new 81 out-of-box admission control rules in Rego are not available by default. This issue is targeted to be addressed in the next release (32.00.xxx).</td></tr><tr><td><strong>—</strong></td><td>AKS clusters with an underscore "_" in the resource group name are detected as vanilla Kubernetes clusters instead of AKS clusters in the host scan results.</td></tr><tr><td><strong>PCSUP-11309</strong></td><td>The <code>--tarball`</code> option in twistcli does not scan for compliance checks. Currently, only vulnerabilities are detected successfully.</td></tr><tr><td><strong>—</strong></td><td>Windows hosts running Defender are reported as unprotected. This issue occurs when Defender is installed on Windows hosts in AWS and Cloud Discovery is configured to scan your environment for protected hosts.</td></tr><tr><td><strong>—</strong></td><td>If you have the same custom compliance rule in use in a host policy (effect: alert) and a container policy (effect: block), the rules will enforce your policy (as expected), but the audit message for a blocked container will incorrectly refer to the host policy and host rule name.</td></tr><tr><td><strong>—</strong></td><td>On the <strong>Radar > Containers</strong>, K3s clusters are not displayed when a Defender is deployed with an empty cluster name. You can view the containers within these clusters under <strong>Non-cluster containers</strong>.</td></tr><tr><td><strong>—</strong></td><td>A <code>404 Not Found error</code> is displayed when performing a sandbox image analysis using older version of twistcli, such as v22.06, with the 22.12 console.</td></tr><tr><td><strong>PCSUP-22448</strong></td><td>DNS audit does not work on AWS app-embedded Fargate Defender. Also, DNS audit works only <strong>Alpine</strong> image and not on any other OS, such as Ubuntu, Debian, and Redhat.</td></tr><tr><td><strong>PCSUP-12197</strong></td><td><p>For an application that originates from an OS package, the vulnerability data for CVEs is sourced from the relevant feed for the OS package. In some cases, like with Amazon Linux and Photon OS, this CVE information is provided in security advisories such as Amazon Linux Security Advisories (ALAS) for Amazon, and PHSA for Photon. In such cases, the correlation for the relevant vulnerabilities is limited.</p><p>As an example, when the application “python” is sourced from an Amazon Python package, CVEs found for the python application (as a binary) will not be correlated with the relevant Amazon CVEs from the ALAS.</p></td></tr><tr><td><strong>-</strong></td><td>Compliance check 6361 fails for hosts running RedHat Enterprise Linux (RHEL) 9. The check to ensure the <code>iptables</code> package is installed fails because <code>iptables</code> was deprecated in RHEL 9 and replaced with the <code>nftables</code> package.</td></tr><tr><td><strong>-</strong></td><td><p>In <strong>Inventory > Compute Workloads</strong>, for users logged in with a role other than the built in system admin role, currently only data about cloud provider managed registry images and VM instances can be viewed. In particular, for such roles currently data about the following types of assets is not displayed:</p><ul><li>Run stage images</li><li>Private registry images</li><li>Build stage images</li><li>On-premises hosts/hosts managed by cloud providers unsupported by Compute</li></ul></td></tr><tr><td><strong>CWP-58896</strong></td><td><ul><li><p>With the support for ACI in cloud discovery, here are the two issues:</p><ul><li>Status: The <code>status</code> field currently utilizes Properties > ProvisioningState, which does not reflect the container status. For more information, refer to <a href="https://learn.microsoft.com/en-us/azure/container-instances/container-state">Azure Container Instances states</a>.</li><li>Defend: The Defend functionality does not support Azure Container Instances (ACI). The Defend functionality is enabled across all accounts and services, and when selected, it redirects to Images > Registry Settings.</li></ul></li></ul></td></tr><tr><td><strong>CWP-58709</strong></td><td><p><strong>Duplicate Admission Rules</strong></p><p>Six admission rules released in Version 32, Update 2 were found to be duplicates of older existing rules. If you need the functionality provided by these rules, we recommend disabling the old rules and using the new corresponding rules, as the older rules will be removed in an upcoming release.</p><p>The old rules and their corresponding new rules are as follows:</p><ul><li><strong>Old rule</strong>: Twistlock Labs - CIS - Pod created in host process ID namespace. <strong>New rule</strong>: Twistlock Labs - PSS - Baseline - Pod with containers that share host process ID (hostPID) namespace</li><li><strong>Old rule</strong>: Twistlock Labs - CIS - Pod created on host IPC namespace. <strong>New rule</strong>: Twistlock Labs - PSS - Baseline - Pod with containers that share host IPC namespace</li><li><strong>Old rule</strong>: Twistlock Labs - CIS - Pod created on host network. <strong>New rule</strong>: Twistlock Labs - PSS - Baseline - Pod that allows containers to share the host network namespace</li><li><strong>Old rule</strong>: Twistlock Labs - Pod created with sensitive host file system mount. <strong>New rule</strong>: Twistlock Labs - PSS - Baseline - Pod created with sensitive host file system mount</li><li><strong>Old rule</strong>: Twistlock Labs - CIS - Privileged pod created. <strong>New rule</strong>: Twistlock Labs - PSS - Baseline - Pod should not run privileged containers</li><li><strong>Old rule</strong>: Twistlock Labs - CIS - Privilege escalation pod created. <strong>New rule</strong>: Twistlock Labs - PSS - Restricted - Pod that allows container privilege escalation</li></ul><p>Note: Even though both the new and old rules are enabled by default, you will not receive duplicate alerts as only the first encountered rule is enforced.</p></td></tr><tr><td><strong>CWP-58350</strong></td><td><p><strong>CVE Exclusions Update</strong></p><p>The following CVEs that are included in the Intelligence Stream feed are ignored: CVE-2022-29583 - GitHub Advisory Database as it is a disputed vulnerability. CVE-2024-3154 - Arbitrary Systemd Property Injection as Defender does not directly use this package.</p></td></tr><tr><td><strong>CWP-52710</strong></td><td>While upgrading consoles from the 30.03 release to a 32.xx release, the error log <code>failed to retrieve "size" specification option value</code> during the migration doesn’t impact the migration process and can be ignored.</td></tr><tr><td><strong>CWP-62297</strong></td><td><p><strong>Twistlock console unable to list image tags from remote repo</strong></p><p>If defender and remote repository are in different subnet, the image tag pulling using <code>podman search --list -tags</code> is not supported with the same access token issued by registry.twistlock.com.</p></td></tr></tbody></table>

## Fixed Issues

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>ISSUE ID</strong></td><td><strong>DESCRIPTION</strong></td></tr><tr><td><p><strong>OS Bundle Package No Longer Overwrites App Version</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.160</mark></p></td><td>Fixed the scanner to prevent OS bundle packages from overwriting the application version during <code>correlateOSPackages</code>. This resolves incorrect vulnerability matches that occurred when OS package metadata incorrectly replaced application version information.</td></tr><tr><td><p><strong>SQLite Read-Only Filesystem No Longer Causes Extraction Failure</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.160</mark></p></td><td>Fixed an issue where a read-only SQLite filesystem caused OS package extraction to fail during image scanning. The scanner now handles read-only filesystem conditions correctly.</td></tr><tr><td><p><strong>Disabled AWS Regions me-south-1 and me-central-1 to Prevent STS Timeouts</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.160</mark></p></td><td>Disabled the <code>me-south-1</code> and <code>me-central-1</code> AWS regions to prevent STS authentication timeouts that affected serverless scanning operations.</td></tr><tr><td><p><strong>Image Scanner Cleans Up Extracted JAR Files</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.160</mark></p></td><td>Fixed the image scanner to delete extracted JAR files immediately after inspection and clean up stale JAR directories on startup. This prevents disk space exhaustion caused by accumulated temporary files.</td></tr><tr><td><p><strong>Defender Connectivity Issue Resolved</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.156</mark></p></td><td><p>Resolved a regression in Quinn update 34.04.145 that makes the Defender set iptables/nftables entries in your environment, even when there is no policy such as Cloud Native Network Security (CNNS) or DNS monitoring requesting it.</p><p>This bug affects all 34.04 Defenders. If the Defender is deployed on Tanzu Application Service (TAS), this may lead to severe connectivity issues.</p><p>The referenced hotfix addresses this issue and ensures that iptables/nftables rules are set only when it is explicitly reflected in the policy.</p></td></tr><tr><td><p><strong>Resolved Issues</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.156</mark></p></td><td><p>Additional Fixes &#x26; Improvements:</p><ul><li>Improved Startup Reliability: This fix addresses an issue where the Defender may appear not to initialize properly in CRI environments, with logs indicating:</li></ul><p><code>Failed to initialize CRI client: runtime version cannot be determined.</code></p><ul><li>Expanded Compliance Support: Added support for nftables in Compliance checks.</li><li>Health Reporting Accuracy: Fixed a bug where the Defender incorrectly reported an "unhealthy" status when operating normally.</li></ul></td></tr><tr><td><p><strong>CWP-64752</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.156</mark></p></td><td><p><strong>Fixed false-positive vulnerability matches for third-party packages</strong></p><p>Fixed scanner to stop incorrectly deriving correlated OS package versions for all third-party package types, preventing false-positive vulnerability matches.</p></td></tr><tr><td><p><strong>CWP-64741</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.156</mark></p></td><td><p><strong>Fixed AVA scan result corruption</strong></p><p>Fixed an issue where trailing output after an AVA (sub) process scan could corrupt scan results.</p></td></tr><tr><td><p><strong>CWP-64729</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.156</mark></p></td><td><p><strong>CNNF rules applied only when enabled</strong></p><p>Fixed Cloud Native Network Firewall to only apply rules when the feature is explicitly enabled, preventing unintended network enforcement.</p></td></tr><tr><td><p><strong>CWP-64712</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.156</mark></p></td><td><p><strong>Fixed container Defender status command</strong></p><p>Fixed the container Defender status command output.</p></td></tr><tr><td><p><strong>CWP-64122</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.156</mark></p></td><td><p><strong>Improved gzip file detection</strong></p><p>Fixed tarball/gzip detection to use magic bytes rather than relying solely on file extension, resolving scan failures for misnamed archives.</p></td></tr><tr><td><p><strong>CWP-64647</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.156</mark></p></td><td><p><strong>Fixed Windows vulnerability assessments</strong></p><p>Fixed incorrect FixedBuild mapping across Windows product IDs in the intelligence builder, resolving inaccurate Windows vulnerability assessments.</p></td></tr><tr><td><p><strong>CWP-64675</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.156</mark></p></td><td><p><strong>Execute yum as root for RPM database access</strong></p><p>Fixed image augmentation to execute yum commands as root when accessing RPM databases via SQLite, resolving scan failures on certain container images.</p></td></tr><tr><td><p><strong>CWP-64702</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.156</mark></p></td><td><p><strong>Fixed crash in compressed layer verification</strong></p><p>Fixed a potential crash caused by an array index out of bounds when verifying compressed layer timestamps during image scanning.</p></td></tr><tr><td><p><strong>CWP-64581</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Resolved rare kernel panic in runtime monitoring</strong></p><p>Fixed a race condition in fsmon that could lead to a kernel panic.</p></td></tr><tr><td><p><strong>CWP-64543</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Fixed WAAS rule forcing defender memory to 4GB</strong></p><p>WAAS rule no longer forces defender max memory to 4GB when enabled on a cluster.</p></td></tr><tr><td><p><strong>CWP-64542</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Fixed defender memory settings preservation</strong></p><p>Defender memory settings are now preserved correctly and no longer decrease unexpectedly.</p></td></tr><tr><td><p><strong>CWP-64538</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Fixed SSH host activity detection on Debian 13</strong></p><p>SSH host activity is now properly detected on Debian 13 systems.</p></td></tr><tr><td><p><strong>CWP-64513</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Improved version detection accuracy for vulnerability assessment</strong></p><p>Defender and twistcli now correctly use OS package version when an app is correlated but its version is missing.</p></td></tr><tr><td><p><strong>CWP-64494</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Reduced false positive CVEs from RPM Epoch detection</strong></p><p>Fixed possible false positive CVE-2023-47038 due to RPM Epoch detection issues.</p></td></tr><tr><td><p><strong>CWP-64486</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Fixed container data display in image tab for agentless scans</strong></p><p>Container data now displays correctly in the image tab when using agentless scanning.</p></td></tr><tr><td><p><strong>CWP-64467</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Resolved yum hang during agentless scanning</strong></p><p>Fixed an issue where the yum command would get stuck during agentless scanning.</p></td></tr><tr><td><p><strong>CWP-64464</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Fixed OCI agentless connectivity in Ashburn region</strong></p><p>Resolved agentless connectivity issues for OCI in the Ashburn region.</p></td></tr><tr><td><p><strong>CWP-64458</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Improved busybox version detection in agentless scans</strong></p><p>Agentless scanning now correctly detects the full busybox version on hosts.</p></td></tr><tr><td><p><strong>CWP-64454</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Multiple defender stability improvements</strong></p><p>Backlog bug fixes for defender stability in Quinn Update 4.</p></td></tr><tr><td><p><strong>CWP-64425</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Fixed app-embedded defender exit on DNS resolution failures</strong></p><p>App-embedded defender no longer exits when handleGetAddrInfoEvent fails.</p></td></tr><tr><td><p><strong>CWP-64402</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Fixed 502 bad gateway error in Runtime Security Module</strong></p><p>Resolved a Runtime Security connectivity issue.</p></td></tr><tr><td><p><strong>CWP-64398</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Fixed image cleanup skipping images with empty hosts</strong></p><p>Image cleanup logic no longer skips images when the hosts field is empty.</p></td></tr><tr><td><p><strong>CWP-64382</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Fixed RHEL 10 defender false iptables error logging</strong></p><p>Host defender using nftables on RHEL 10 no longer logs errors about missing iptables.</p></td></tr><tr><td><p><strong>CWP-64380</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Fixed Cloud Run functions appearing in Radar when feature flag is off</strong></p><p>Functions created with gcloud run are no longer listed in Radar view when the feature flag is disabled.</p></td></tr><tr><td><p><strong>CWP-64367</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Fixed ServiceNow alert integration reliability</strong></p><p>Resolved issues with alerts failing to send to ServiceNow.</p></td></tr><tr><td><p><strong>CWP-64359</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Fixed CNNS container summary count mismatch</strong></p><p>CNNS for containers now correctly sums up to match its detail counts.</p></td></tr><tr><td><p><strong>CWP-64358</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Fixed incident audit CSV serial number column</strong></p><p>The twistlock_incidents_audit CSV file serial number column now increments correctly instead of showing constant #0.</p></td></tr><tr><td><p><strong>CWP-64319</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Fixed registry scan handling of long image tags</strong></p><p>Registry scan image cleanup no longer fails when tag exceeds 128-character limit.</p></td></tr><tr><td><p><strong>CWP-64237</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Fixed consistent WAAS protection for Istio traffic</strong></p><p>Istio traffic is now consistently protected by defender when using WAAS.</p></td></tr><tr><td><p><strong>CWP-64233</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Fixed registry scanner error message formatting</strong></p><p>Registry scanner log now shows proper image pull error messages instead of %!s(MISSING).</p></td></tr><tr><td><p><strong>CWP-64167</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Resolved log flooding from missing container images</strong></p><p>Fixed "Failed to find image for container" messages flooding the log.</p></td></tr><tr><td><p><strong>CWP-64117</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Fixed ECS EXTERNAL launch type handling</strong></p><p>Cloud Discovery now correctly handles ECS EXTERNAL launch type.</p></td></tr><tr><td><p><strong>CWP-64116</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Fixed auto-defend rules custom role filtering</strong></p><p>Host and serverless auto-defend rules are now properly filtered by custom role.</p></td></tr><tr><td><p><strong>CWP-64068</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Fixed agentless scan status persistence after refresh</strong></p><p>Agentless last scan field no longer disappears on page refresh.</p></td></tr><tr><td><p><strong>CWP-64402</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Fixed 502 bad gateway error in Runtime Security Module</strong></p><p>Resolved a Runtime Security connectivity issue.</p></td></tr><tr><td><p><strong>CWP-64398</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Image cleanup logic skips images when hosts field is empty</strong></p><p>Fixed an issue where images that have been deleted from their namespaces are still being shown in the console.</p></td></tr><tr><td><p><strong>CWP-64117</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Cloud Discovery limitation resolved</strong></p><p>ECS task definition containers with <code>launchType: External</code> that are listed in the Inventory are not present in the Prisma Cloud Console ( Runtime Security > Radar). This issue is now fixed.</p></td></tr><tr><td><p><strong>CWP-63717</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Filepaths of secrets found by scanners other than agentless contain prefix of scan directory</strong></p><p>Resolved an issue with the Vulnerability scan report for registry images showing vulnerabilities that are tagged to an image path which does not actually exist on the image.</p></td></tr><tr><td><p><strong>CWP-64258</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Cloud Radar resource reporting</strong></p><p>Fixed an issue with the inaccurate reporting for Defended resources.</p></td></tr><tr><td><p><strong>CWP-64116</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Console - host and serverless auto-defend rules are not filtered by custom role</strong></p><p>Resolved an issue with a custom role user not being able to access certain specifications when working with Defender Auto-Deploy rules.</p></td></tr><tr><td><p><strong>CWP-64265</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Macro fields not populated</strong></p><p>Fixed an issue with some macro fields not being populated, when a Compliance trigger is set up to forward alerts via Webhook to Service Now.</p></td></tr><tr><td><p><strong>CWP-64459</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>NF table support</strong></p><p>Following the addition of NF tables support in WAAS, NF tables support is also now available for Defender (CNNF and Runtime Policy).</p><p><strong>Note:</strong> Open issues relating to the Compliance scan flow, will be addressed in a subsequent release.</p></td></tr><tr><td><p><strong>CWP-64543</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Defender Memory Settings</strong></p><p>This fix prevents memory decrease if it is already set.</p></td></tr><tr><td><p><strong>CWP-63255</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.04.145</mark></p></td><td><p><strong>Live Status Check Limitation</strong></p><p><mark style="background-color:orange;">Secure the Infrastucture</mark></p></td></tr><tr><td>Resolved an issue where if you have only configured <strong>VNet flow logs</strong>, the <strong>Flow Log</strong> component displays a red status (error) during the Live Status Check.</td><td><p><strong>Unused Defender packages</strong></p><p>Removed multiple unused packages to reduce exposure to CVEs.</p></td></tr><tr><td><p><strong>CWP-64867</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.03.138</mark></p></td><td><p><strong>RPM database patch</strong></p><p>Added a sqlite3 patch for RPM database (rpmdb) to address package metadata extraction issues in RPM-based images.</p></td></tr><tr><td><p><strong>PCSUP-29054</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.03.138</mark></p></td><td><p><strong>Standardized Non-Privileged User ID for Defender CLI</strong></p><p>To enhance security across all supported operating systems, the Defender component will now use the standardized, <strong>non-privileged</strong> User ID (1100) when executing Command Line Interface (CLI) commands.</p></td></tr><tr><td><p><strong>CWP-63569</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.03.138</mark></p></td><td><p><strong>Account-level reporting of scan date and time</strong></p><p>The scan start and end date and time were earlier reported at the region level and weren’t precise in some situations. This fix ensures accurate reporting of scan start and end date and time at the individual account level.</p></td></tr><tr><td><p><strong>CWP-63632</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.03.138</mark></p></td><td><p><strong>Release name for Windows Server 2025 doesn’t resolve correctly</strong></p><p>This issue is fixed now. The release name for Windows Server 2025 displays correctly.</p></td></tr><tr><td><p><strong>CWP-64185</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.03.138</mark></p></td><td><p><strong>Improved defender stability with Read-only 'runc' paths</strong></p><p>Previously, in crio environments, if the paths to <code>runc</code> were located in read-only directories, the defender would delegate the calls to the first runtime it found, increasing the risk of node instability.</p><p>This issue has now been resolved, and defender will use the default runtime. To properly deploy the newer version containing this fix, follow these steps:</p><ol><li>Remove the existing defender daemonset.</li><li>Ensure that no ZZ-twistlock.conf file is present in /etc/crio/crio.conf.d. If it exists, delete it.</li><li>Restart the affected node.</li><li>Deploy the new defender.</li></ol></td></tr><tr><td><p><strong>CWP-64196</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.03.138</mark></p></td><td><p><strong>App-embedded Defender crashes on thread termination</strong></p><p>The App-embedded defender crashes if the application it is protecting, or a thread of the application, terminates while it is connecting to the app-embedded defender.</p></td></tr><tr><td><p><strong>CWP-61530</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.02.133</mark></p></td><td><p><strong>False positives for Oracle images and hosts</strong></p><p>The issue with CVE matching for Oracle images and hosts, which caused false positives due to missing Oracle module information, is fixed now.</p></td></tr><tr><td><p><strong>CWP-63043</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.02.133</mark></p></td><td><p><strong>False positives for OpenShift images</strong></p><p>False positives were reported for OpenShift images due to incorrect parsing of the release label.</p><p>This issue is fixed now.</p></td></tr><tr><td><p><strong>CWP-63194</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.02.133</mark></p></td><td><p><strong>False positives due to incorrect Red Hat version comparison</strong></p><p>Added support for the epoch prefix in Red Hat images. Previously, the epoch was omitted during image scanning, causing version comparisons to ignore it and resulting in false positives. This fix ensures the epoch value is included, allowing accurate version comparisons and preventing incorrect vulnerability matches.</p></td></tr><tr><td><p><strong>CWP-63341</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.02.133</mark></p></td><td><p><strong>Defender periodic scans are not disabled when the scan interval is set to 0</strong></p><p>Even when the scan interval for images, containers and hosts is set to 0 on the Manage > System > Scan page in the UI, the defender continues to execute periodic scans every 24 hours.</p><p>This issue is fixed now.</p></td></tr><tr><td><p><strong>CWP-63479</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.02.133</mark></p></td><td><p><strong>Incorrect value in the CaaS containers column</strong></p><p>The value in the CaaS containers column in the Registry images table on the Monitor > Vulnerabilities > Image > Registries page was not updated if the Fargate task was no longer available in Prisma Cloud.</p><p>This issue is fixed now.</p></td></tr><tr><td><p><strong>CWP-63695</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.02.133</mark></p></td><td><p><strong>Serverless scanning of Python packages in the requirements.txt file</strong></p><p>Previously, dependencies in the requirements.txt file were not considered during vulnerability and compliance scans of Azure serverless functions and GCP Cloud Run functions for Python. Now, packages specified in requirements.txt are also included in the scan.</p><p>Note that for packages in the file to be taken into consideration, specific package versions need to be specified using "==". For example: docopt == 0.6.1</p></td></tr><tr><td><p><strong>CWP-63711</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.02.133</mark></p></td><td><p><strong>URLs for RHEL repos</strong></p><p>The issue with CVE matching that caused false positives when relative URLs for Red Hat repositories are used is fixed now.</p></td></tr><tr><td><p><strong>CWP-63808</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.02.133</mark></p></td><td><p><strong>Gateway timeout while loading feeds</strong></p><p>Feed changed notifications to Defenders are now batched and spread to prevent 504 Gateway Timeout errors from concurrent downloads. Defenders also use Exponential Backoff with Jitter for retries.</p></td></tr><tr><td><p><strong>CWP-63880</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.02.133</mark></p></td><td><p><strong>Base image history tagging</strong></p><p>Scanning over 50 digests under one rule caused older base image digests to be deleted, removing base image links. The Base Image tag incorrectly remained under the Layers tab for these images. This has been fixed: the Base Image tag is now correctly removed from the Layers tab for images whose original base images were overridden.</p></td></tr><tr><td><p><strong>CWP-63887</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.02.133</mark></p></td><td><p><strong>False positives for Amazon ALAS CVE advisories</strong></p><p>False positives were generated because of the change in the URL for the Amazon ALAS CVE advisory file. The underlying cause for these false positives is fixed now.</p></td></tr><tr><td><p><strong>CWP-63924</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.02.133</mark></p></td><td><p><strong>Node crashes on OpenShift 4.18 clusters</strong></p><p>Node crashes may happen on OpenShift 4.18 clusters in case the defender is configured with a block policy.</p><p>This happens because OpenShift 4.18 has changed the default runtime implementation from <code>runc</code> to <code>crun</code>, and the defender didn’t handle that change correctly.</p><p>The issue is fixed now.</p></td></tr><tr><td><p><strong>CWP-63935</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">34.02.133</mark></p></td><td><p><strong>JWT tokens with Japanese characters fail to authenticate</strong></p><p>Prisma Cloud roles with names that included Japanese characters caused an error.</p><p>This issue has been fixed.</p></td></tr><tr><td><p><strong>CWP-63688</strong></p><p><mark style="background-color:orange;">34.01.132</mark></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p></td><td><p><strong>No default outbound access for Azure Agentless Scanning</strong></p><p>Microsoft Azure is retiring the facility to provide default outbound access. See the <a href="https://azure.microsoft.com/en-us/updates?id=default-outbound-access-for-vms-in-azure-will-be-retired-transition-to-a-new-method-of-internet-access">Microsoft announcement</a> for more details.</p><p>This change will adversely impact Prisma Cloud’s ability to perform Agentless Scanning. To mitigate this issue, Prisma Cloud agentless scanners will employ Network Address Translation (NAT) gateway to access the console.</p><p>To enable Prisma Cloud agentless scanners to use the NAT gateway, the following additional permissions have been added to the onboarding Terraform template:</p><ul><li><code>Microsoft.Network/publicIPAddresses/read</code></li><li><code>Microsoft.Network/publicIPAddresses/write</code></li><li><code>Microsoft.Network/publicIPAddresses/delete</code></li><li><code>Microsoft.Network/natGateways/read</code></li><li><code>Microsoft.Network/natGateways/write</code></li><li><code>Microsoft.Network/natGateways/delete</code></li></ul><p>This fix ensures that Prisma Cloud Compute uses NAT gateway for agentless scanning.</p></td></tr><tr><td><p><strong>CWP-63687</strong></p><p><mark style="background-color:orange;">34.01.132</mark></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p></td><td><p><strong>Enhanced AWS resource-level permissions for copying Amazon EBS snapshots</strong></p><p>Amazon AWS has announced enhanced resource-level permissions for copying Amazon EBS snapshots. Please see the <a href="https://aws.amazon.com/blogs/storage/enhancing-resource-level-permissions-for-copying-amazon-ebs-snapshots/">Amazon announcement</a> for more details. This change impacts Prisma Cloud agentless scanning of AWS compute instances.</p><p>To avoid issues that can arise from this change, the following statement has been replaced in the onboarding CFT:</p><pre><code>"Condition": {
            "StringEquals": {
                "aws:RequestTag/created-by": "prismacloud-agentless-scan"
                }
            },
            "Action": [
                "ec2:CopySnapshot"
            ],
            "Resource": [
                "arn:aws:ec2:*::snapshot/*"
            ],
            "Effect": "Allow",
            "Sid": "PrismaCloudPrismaCloudAgentlessCopySnapshot8"
        }
</code></pre><p>With this statement:</p><pre><code>{
            "Condition": {
                "StringEquals": {
                    "aws:RequestTag/created-by": "prismacloud-agentless-scan"
                }
            },
            "Action": [
                "ec2:CopySnapshot"
            ],
            "Resource": [
                "arn:aws:ec2:*::snapshot/${*}"
            ],
            "Effect": "Allow",
            "Sid": "PrismaCloudPrismaCloudAgentlessCopySnapshot8"
        },
        {
            "Condition": {
                "StringEquals": {
                    "aws:ResourceTag/created-by": "prismacloud-agentless-scan"
                }
            },
            "Action": [
                "ec2:CopySnapshot"
            ],
            "Resource": [
                "arn:aws:ec2:*::snapshot/snap-*"
            ],
            "Effect": "Allow",
            "Sid": "PrismaCloudPrismaCloudAgentlessCopySnapshot9"
        }
</code></pre><p>This change ensures that Prisma Cloud uses the enhanced resource-level permissions announced by Amazon AWS.</p><p>The statement changes won’t be shown in the status message as the status check is performed only on the action parameter in the statement; not the other parameters.</p></td></tr><tr><td><p><strong>RLP-155307</strong></p><p><mark style="background-color:orange;">Fixed in 25.6.1</mark></p></td><td>Previously, the Prisma Cloud Chronicles email was not sent to all System Administrators. With this fix, now every System Administrator will receive the Chronicles email and if they do not wish to receive it, they have an option to <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/administration/define-prisma-cloud-enterprise-settings#unsubscribe-chronicles">unsubscribe</a>.</td></tr><tr><td><p><strong>CWP-63359</strong></p><p><mark style="background-color:orange;">34.01.126</mark></p></td><td><p><strong>#IngressNightmare vulnerabilities</strong></p><p>An enhanced mechanism for identification of packages helps in improved detection of vulnerabilities, such as the #ingressnightmare vulnerability issue.</p><p>This enhancement allows for earlier detection and remediation, proactively mitigating potential exploits.</p></td></tr><tr><td><p><strong>CWP-63421</strong></p><p><mark style="background-color:orange;">34.01.126</mark></p></td><td><p><strong>The "defended" status for ECS task definitions inocorrectly set to <code>false</code></strong></p><p>ECS task definition entities discovered as part of cloud discovery have a "defended" status. This "defended" status field is set to true if a Fargate defender is detected as installed in one of the containers in the task definition. This "defended" status field was incorrectly set to <code>false</code> even when a Fargate defender was installed in one of the containers.</p><p>This issue is fixed now.</p></td></tr><tr><td><p><strong>RLP-154631</strong></p><p><mark style="background-color:orange;">Fixed in 25.3.1</mark></p></td><td><p><strong>Agentless Module Impacts Credit Consumption</strong></p><p>Resolved an issue with Agentless Scanning worker Virtual Machines (VMs) being counted towards Prisma Cloud credit consumption. Previously, credit computation incorrectly included credits attributed to worker VMs. While, the impact to overall credit consumption was negligible, the Cloud Security Posture Management (CSPM) module now identifies worker VMs spun up by the Agentless module. Consequently, credits attributed to Agentless Scanning worker VMs are no longer included in the credit consumption data that is reported.</p></td></tr><tr><td><p><strong>CWP-59903</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p></td><td><p><strong>Cleanup of system resources after registry scanning</strong></p><p>A new scanner tag is generated when an image is pulled for scanning. In certain cases, this tag was not properly removed after the scan completed.</p><p>This issue is fixed now. Improvements to the registry scan mechanism ensure a proper cleanup of system resources after scanning.</p></td></tr><tr><td><p><strong>CWP-62590</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p></td><td><p><strong>Prisma Cloud reported incorrect fix dates for RedHat vulnerabilities</strong></p><p>This issue occurred for vulnerabilities reported as fixed through RedHat feeds in the VEX format. This issue is fixed now.</p></td></tr><tr><td><p><strong>CWP-60416</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p></td><td><p><strong>Incorrect parsing of Ruby advisories that use RC versions</strong></p><p>Incorrect parsing of Ruby advisories that use RC versions (such as '3.0.0-rc.1') caused false positive CVE reporting.</p><p>This issue is fixed now.</p></td></tr><tr><td><p><strong>CWP-61862</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p></td><td><p><strong>An incorrect fix date is reported for CVEs that did not provide a fix date initially</strong></p><p>An incorrect fix date is reported for CVEs that did not provide a fix date initially and were then reopened and fixed (again) with a fix date that is later than the date when the issue was first reported as fixed. Prisma Cloud reported the date when the issue was first reported as fixed and did not update the fix date after the issue was reopened and fixed with a different date.</p><p>This issue is fixed now.</p></td></tr><tr><td><p><strong>CWP-62128</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p></td><td><p><strong>Changes in the Ubuntu feed caused false positives in some situations</strong></p><p>Changes in the Ubuntu feed format added an asterisk in the condition for some CVE entries. This was not parsed correctly and led to false positives.</p><p>This issue is fixed now.</p></td></tr><tr><td><p><strong>CWP-62193</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p></td><td><p><strong>Incorrect fixed version reported for some CVEs reported in NVD</strong></p><p>An issue with the parsing of NVD data led to an incorrect fixed version being reported in some cases.</p><p>This issue is fixed now.</p></td></tr><tr><td><p><strong>CWP-62290</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p></td><td><p><strong>Fixed Debian issues that have a CVE with the "nodsa\_reason" property set to "ignored" are reported as a vulnerability</strong></p><p>Debian CVEs that have an Urgency of "unimportant" or a "nodsa\_reason" setting of "ignored" in the Debian feed were not reported as vulnerabilities when detected by Prisma Cloud Compute.</p><p>This issue is fixed now. Now, such CVEs will be reported as vulnerabilities with the status 'will not fix' by Prisma Cloud Compute.</p></td></tr><tr><td><p><strong>CWP-62394</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p></td><td><p><strong>In a few situations serverless credits were consumed even after disabling the serverless functionality</strong></p><p>In setups/tenants that had a particular (core-serverless-scan-concurrent-flow-enabled) setting enabled, serverless scan results were not deleted. This caused some serverless credits to be consumed even after the serverless feature was disabled in the tenant.</p><p>This issue is fixed now.</p></td></tr><tr><td><p><strong>CWP-62552</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p></td><td><p><strong>Defender is unable to identify the OpenShift installation on the OpenShift nodes</strong></p><p>The OpenShift version is not available in the RELEASE\_VERSION environment variable in the running 'openshift-tuned' process due to a change in OpenShift. It has now been replaced by a new process called cluster-node-tuning-operator that receives 'openshift-tuned' via command line args. Defenders were unable to detect the OpenShift installation due to this change.</p><p>This issue is fixed now.</p></td></tr><tr><td><p><strong>CWP-62562</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p></td><td><p><strong>Fixed RHEL issues are incorrectly flagged as unresolved due to an issue in mapping CPEs to RHEL repositories</strong></p><p>After Redhat switched to the new VEX format for reporting CVEs and fixes, some fixed RHEL issues were incorrectly flagged as unresolved due to an issue in mapping CPEs to RHEL repositories.</p><p>This issue is fixed now.</p></td></tr><tr><td><p><strong>CWP-62570</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p></td><td><p><strong>Base images when scanned separately, displayed vulnerabilities that were not present</strong></p><p>The scan results for some base images that were scanned separately incorrectly displayed vulnerabilities–even though no vulnerabilities were present in those base images. Whereas, images using those base images reported the vulnerabilities correctly and did not display any vulnerabilities for the underlying base images.</p><p>This issue is fixed now.</p></td></tr><tr><td><p><strong>CWP-62575</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p></td><td><p><strong>False positives observed for vulnerabilities reported in the RedHat VEX format without specific distro-release information</strong></p><p>Vulnerabilities reported in the RedHat VEX format without specific distro-release information generated false positives.</p><p>This issue is fixed now.</p></td></tr><tr><td><p><strong>CWP-62609</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p></td><td><p><strong>Including packages of a Go application that are part of the main module in the scan results</strong></p><p>Previously, Prisma Cloud scan results did not include Go packages that were part of the main module, resulting in the omission of these packages and their associated vulnerabilities in the console.</p><p>This issue has now been resolved.</p></td></tr><tr><td><p><strong>CWP-62668</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p></td><td><p><strong>Compliance check 598 always fails for Kubernetes containers running Redis if the container was created without using –requirepass parameter</strong></p><p>Compliance check 598 fails and shows the error “App uses weak or default password” for Kubernetes containers running redis even though the container uses a strong password. This issue occurs if the container was created without using –requirepass parameter.</p><p>This issue is fixed now.</p></td></tr><tr><td><p><strong>CWP-62883</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p></td><td><p><strong>The 'fix status' column in the vulnerability report is blank for a few CVEs</strong></p><p>The 'fix status' column in the vulnerability report is blank for a few CVEs due to missing information in the NVD vulnerability feed.</p><p>This issue is fixed now. The required information is now gathered using a separate NVD function.</p></td></tr><tr><td><p><strong>CWP-62884</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p></td><td><p><strong>Stale unpaired cloud security agents (CSAs) are not deleted</strong></p><p>This issue is fixed now.</p></td></tr><tr><td><p><strong>CWP-62994</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p></td><td><p><strong>Container protected by an App embedded defender with File System monitoring enabled crashes when an SSH connection is made to it</strong></p><p>Container protected by an App embedded defender with File System monitoring enabled crashes when an SSH connection is made to it.</p><p>This issue is fixed now.</p></td></tr><tr><td><p><strong>CWP-63032</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p></td><td><p><strong>Support Jenkins LTS CVEs detection</strong></p><p>Prisma Cloud now extracts software edition information from CVEs and utilizes it for scanning. This enables Prisma Cloud scanners to differentiate software editions, such as Jenkins LTS releases from regular Jenkins releases, and accurately identify vulnerabilities.</p></td></tr><tr><td><p><strong>CWP-63033</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p></td><td><p><strong>Improved Vulnerability Reporting for Mirrored RHEL Repositories</strong></p><p>Repository identifiers often change when repositories are mirrored from Red Hat’s Content Delivery Network (CDN) to alternative cloud environments, like AWS. This may result in inaccurate vulnerability reporting.</p><p>The issue has now been resolved by extracting the relative URLs of repositories from the image and comparing them with the corresponding relative URLs provided in the repository-to-CPE mapping file for CVE matching.</p></td></tr><tr><td><p><strong>CWP-63110</strong></p><p><mark style="background-color:orange;">Fixed in 34.00.137</mark></p></td><td><p><strong>Incorrect data is returned when Prisma Cloud roles that have read only access to Windows hosts try to access and retrieve data from those Windows hosts</strong></p><p>Incorrect data is returned when Prisma Cloud roles that have read only access to Windows hosts try to access and retrieve cloud metadata from those Windows hosts.</p><p>This issue is fixed now.</p></td></tr><tr><td><p><strong>PCSUP-26234</strong></p><p><mark style="background-color:orange;">Fixed in 33.03.138</mark></p></td><td><p><strong>Storage issues during the Defender shutdown process</strong></p><p>The Defender shutdown process in versions 32.02 through 32.05 (inclusive) shut down the storage component using a third-party package. This package used a flag to force storage to unmount during the shutdown, which lead to storage corruption in some cases. This issue was resolved in 32.06 by modifying the shutdown process to perform a non-forced unmount.</p><p>For any Defender instance from the affected versions that has already been shut down, upgrade the defender to a non-affected version (32.06 or later) and then reboot the node to clean up any storage corruption.</p></td></tr><tr><td><p><strong>CWP-62576</strong></p><p><mark style="background-color:orange;">Fixed in 33.03.138</mark></p></td><td><p><strong>Resolving Severity Scores and CVE Links for GO Vulnerabilities in OSV Feed</strong></p><p>When processing CVEs sourced from both the GO and GitHub Security Advisories (GHSA) formats in the Open Source Vulnerability (OSV) feed, incorrect severity scores and CVE links were assigned.</p><p>This issue is resolved. The fix ensures that the severity scores, CVSS values, and CVE links for GO vulnerabilities are accurate and aligned with the official OSV GO feed.</p></td></tr><tr><td><p><strong>CWP-62313</strong></p><p><mark style="background-color:orange;">Fixed in 33.02.134</mark></p></td><td><p><strong>Improved Status Filter for Cloud Security Agent Page</strong></p><p>The "Status" filter under <strong>Prisma UI > Manage > Defenders > Cloud Security Agent</strong> was displaying only the statuses present in the table, instead of all possible statuses.</p><p>This issue has been resolved. The CSA status filter now shows a list of all available statuses: Connected, Disconnected, and Lost. This ensures users can filter the table by any status.</p></td></tr><tr><td><p><strong>CWP-35710</strong></p><p><mark style="background-color:orange;">Fixed in 33.02.134</mark></p></td><td><p><strong>Removing Namespaces After Resource Deletion</strong></p><p>In some cases, namespaces remained visible even after all resources within them had been deleted. This led to incorrect vulnerability assessments as the namespaces were not properly removed from the results. This issue is now resolved.</p></td></tr><tr><td><p><strong>CWP-62296</strong></p><p><mark style="background-color:orange;">Fixed in 33.02.134</mark></p></td><td><p><strong>Consistent Vulnerability Data for Red Hat-Sourced Packages</strong></p><p>Certain vulnerabilities for Red Hat packages showed a Red Hat severity but CVSS scores from NVD.</p><p>This mismatch is now resolved. The fix ensures that both the severity and CVSS score now align with Red Hat’s data, eliminating inconsistencies.</p></td></tr><tr><td><p><strong>CWP-62084</strong></p><p><mark style="background-color:orange;">Fixed in 33.01.137</mark></p></td><td><p><strong>Updating the list of binaries exposed to a vulnerability after rerunning a scan</strong></p><p>Rerunning a scan didn’t update the binary packages exposed to a vulnerability. This issue is fixed now.</p></td></tr><tr><td><p><strong>CWP-61947</strong></p><p><mark style="background-color:orange;">Fixed in 33.01.137</mark></p></td><td><p><strong>Boot volume encryption in agentless scanning</strong></p><p>Fixed an issue with the agentless scanner boot volume default encryption.</p></td></tr><tr><td><p><strong>CWP-61606</strong></p><p><mark style="background-color:orange;">Fixed in 33.01.137</mark></p></td><td><p><strong>CSV Export Compatibility with Excel</strong></p><p>The exported CSV file from the <strong>Monitor > Vulnerabilities > Images > Deployed</strong> page could not be opened in Excel when the Hosts field exceeded the maximum character limit of 32,768 per column.</p><p>This issue is resolved. The fix ensures that the CSV now lists all the hostnames running the same image. However, if the total length exceeds 32,757 characters, the list is truncated, and the number of truncated hostnames is indicated in the CSV.</p></td></tr><tr><td><p><strong>CWP-59281</strong></p><p><mark style="background-color:orange;">Fixed in 33.01.137</mark></p></td><td><p><strong>Improved vulnerability reporting for Debian images</strong></p><p>When scanning Debian images, Prisma Cloud occasionally missed some CVEs related to specific package versions. This issue is fixed.</p><p>The fix prioritizes CVE matches from the security repository and Prisma Cloud now reports all previously missing CVEs for packages in Debian images.</p></td></tr><tr><td><p><strong>CWP-58952</strong></p><p><mark style="background-color:orange;">Fixed in 33.01.137</mark></p></td><td><p><strong>Improved vulnerability detection for multiple Python versions</strong></p><p>In previous versions of Defender, vulnerabilities were only detected and reported for a single Python installation on a host, even if multiple Python versions were installed. This resulted in False Negatives (FN), where vulnerabilities in other Python versions were missed.</p><p>The issue is fixed. Prisma Cloud will now scan and report vulnerabilities for each installed Python version on a host.</p></td></tr><tr><td><p><strong>CWP-59654</strong></p><p><mark style="background-color:orange;">Fixed in 33.01.137</mark></p></td><td><p><strong>Support for Amazon Linux CVEs</strong></p><p>Previously, Prisma Cloud reported several false positive vulnerabilities for Amazon Linux CVEs that were marked as "not affected" by Amazon.</p><p>Prisma Cloud now fully supports CVEs classified as “not affected” by Amazon, improving the accuracy of vulnerability reporting for Amazon products and resolving the false positive issue. The supported Amazon Linux distributions include Amazon Linux, Amazon Linux 2, and Amazon Linux 2023.</p><p>Prisma Cloud does not support CVEs labeled as "pending fix" or "no fix planned," as Amazon does not provide the required package version details for precise CVE status reporting.</p></td></tr><tr><td><mark style="background-color:orange;">Fixed in 33.00.169</mark></td><td><p><strong>Improvements in Amazon Linux Vulnerability Reporting</strong></p><p>Vulnerability information for many Amazon Linux CVEs lacked consistency across different Intelligence Stream updates, including changes in severity levels and fixed status versions. To address this, several key improvements were made, including enhanced consistency across scans, improved handling of duplicated CVEs, accurate ALAS to CVE conversion, and refined kernel package rules. These changes ensure more reliable and actionable vulnerability information for all Amazon distributions and kernel packages.</p></td></tr><tr><td><mark style="background-color:orange;">Fixed in 33.00.169</mark></td><td><p><strong>Standardizing Java Versioning for Accurate Vulnerability Mapping</strong></p><p>Inconsistent version numbering for Java products led to several false positives in Prisma Cloud security scans. To ensure accurate mapping of vulnerabilities to Java versions, all Java product versions will be normalized to the standard 1.x format. For example, in the <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-21930">CVE-2023-21930</a> entry on the National Vulnerability Database (NVD), OpenJDK 8 will map to Java 1.8.</p></td></tr><tr><td><mark style="background-color:orange;">Fixed in 33.00.169</mark></td><td><p><strong>Enhanced Detection for Minor Versions in Alpine Packages</strong></p><p>Alpine’s security database shows vulnerabilities for each Alpine package, including fixed versions and associated CVEs. However, when the CVE does not include a fixed version, the rule misses vulnerabilities in minor versions, leading to incomplete vulnerability coverage. This issue has been fixed. The updated vulnerability rules ensure that minor versions are included, even when no specific fixed version is available.</p></td></tr><tr><td><mark style="background-color:orange;">Fixed in 33.00.169</mark></td><td><p><strong>CVEs Resolved in Release 33.00</strong></p><p>While alerts were generated for CVE-2024-6104 and CVE-2024-29018, Prisma Cloud was not directly vulnerable and remained safe to use. The alerts have been resolved in Prisma Cloud release 33.00.</p></td></tr><tr><td><mark style="background-color:orange;">Fixed in 33.00.169</mark></td><td><p>Customers could pass invalid data to the <code>v1/alert-profile</code> and <code>collections</code> APIs. To address this issue, the following validations have been added:</p><ul><li><p>For <code>v1/alert-profiles</code> APIs:</p><ul><li>The name parameter must be less than 50 characters.</li><li>The email address must be valid.</li><li>The port parameter must not be less than 1.</li><li>The recipient’s email address must be valid.</li></ul></li><li><p>For <code>Collections</code>:</p><ul><li>The name parameter must be less than 50 characters.</li><li>The description parameter must be less than 200 characters.</li></ul></li></ul></td></tr><tr><td><mark style="background-color:orange;">Fixed in 33.00.169</mark></td><td><p><strong>Improved Image Scanning</strong></p><p>If the Defender disconnects while scanning an image that has the same tag, registry, repository, and credentials, it can lead to multiple scan requests of the same image. In addition, a race condition could sometimes prevent the image from being properly removed from the host container registry after scanning. This fix ensures that only one scan is performed per image, even if multiple scan requests are triggered by disconnections. This reduces the load on the Defender.</p><p>The fix also addresses the race condition. However, not all possible race conditions are addressed:</p><ul><li>If the same image is scanned in different repositories or registries, race conditions are not addressed by this fix.</li><li>If the same image is scanned in the same repository and registry but with different tags, the fix does not handle potential race conditions.</li></ul></td></tr><tr><td><mark style="background-color:orange;">Fixed in 33.00.169</mark></td><td>Previously, users experienced intermittent timeouts in a shorter timeframe than the default inactivity period, which was set to 300 minutes under <strong>Settings > Enterprise Settings > User Idle Timeout > CX</strong>. This issue has now been resolved, and all Prisma Cloud tabs log out only after 300 minutes of inactivity.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 33.00.169</mark></td><td><p><strong>Agentless Scanning - Support for OCI root compartment scans</strong></p><p>OCI instances deployed in the root compartment were not scanned during Agentless scans. Instances in child compartments were scanned as expected, but root compartment instances were excluded without error. This issue is fixed-all compartments, including the root, are now scanned successfully.</p></td></tr><tr><td><mark style="background-color:orange;">Fixed in 33.00.169</mark></td><td><p><strong>Compliance IDs 440/441 in Lamba Scans</strong></p><p>Compliance IDs 440/441 triggered false positives during a serverless Lambda scan for kms permissions. This issue is fixed.</p></td></tr><tr><td><mark style="background-color:orange;">Fixed in 33.00.169</mark></td><td><p><strong>Improved Clarity in Incident Log Messages</strong></p><p>In certain cases, the command that triggered an incident was missing from the incident capture flow. This caused the messages in the Incident Explorer to occasionally lack clarity, leading to incomplete logs. The fix ensures that executed commands are now included in audit reports when available. Additionally, it prevents the generation of incomplete reports if the command is missing</p></td></tr><tr><td><mark style="background-color:orange;">Fixed in 33.00.169</mark></td><td><p><strong>Reduced Registry Scan Duration</strong></p><p>Prisma Cloud sometimes experienced extended registry scan times due to certain images not being correctly recognized. This led to the registry scan missing cached images, resulting in longer scan durations. The cache miss happened because the image ID hash from the Container Runtime API was missing the sha256 prefix. The issue has now been fixed by using the hash from the registry scan request sent by the Console, when available. This ensures cache hits and enhances scan performance.</p></td></tr><tr><td><mark style="background-color:orange;">Fixed in 33.00.169</mark></td><td>Exporting discovered APIs to OpenAPI CSV files from the <strong>Runtime > Monitor > WAAS > API discovery > Export CSV</strong> page failed if the API had unsupported methods such as PURGE. This issue is fixed.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 33.00.169</mark></td><td>Previously, a "buffer full" error was reported with an HTTP 500 status code, when the same port was reused in a specific order across multiple apps in a single WAAS rule. This issue is fixed now.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 33.00.169</mark></td><td>Fixed an issue where compliance alerts for malware (Compliance ID 455) did not appear in daily email reports despite failed resources being detected. This fix ensures accurate reporting for agentless scans.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 33.00.169</mark></td><td><p><strong>Agentless Scanning - Resource Group Creation in Target Azure Account during Hub Scan Mode</strong></p><p>Fixed an issue where resource groups were created in the target account during Azure agentless Hub scan mode. Now, resource groups are no longer created in the target account when a hub account is defined on it.</p></td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.07</mark></td><td>The issue related to interruption in the communication between a defender and the console—​that was introduced by the newly introduced fail-safe mechanism aimed to prevent any impact to customer traffic or downtime—​is resolved. The fix requires you to upgrade the Console and the Defenders to version 33.00.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.07</mark></td><td><p>For some GO package CVEs, Prisma Cloud did not completely report all the affected versions, particularly when multiple version ranges were involved, resulting in occasional false negatives.</p><p>This issue is fixed. Prisma Cloud now reports all the affected versions for GO package CVEs.</p></td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.07</mark></td><td><p><strong>Add collections filtering behavior</strong></p><p>Previously, image scan filtering by collection restricted the collections listed in the Collections column to the collection selected in the filter. This issue is fixed now. Now, for each image, all related collections of the filtered images are displayed, even when a specific collection filter is applied.</p></td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.07</mark></td><td><p>When a JAR file with a group ID is used as a dependency in other JAR files within the same image, Prisma Cloud might fail to properly identify or match CVEs to those JAR files.</p><p>This issue is resolved. Prisma Cloud now correctly handles group IDs in both the Defender and the Console, improving the ability to identify CVEs accurately for such JAR files.</p></td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.07</mark></td><td>A new optional query parameter <code>includeLabels</code> is added to the <a href="https://pan.dev/prisma-cloud/api/cwpp/get-containers-download/">Download Container Scan Results</a> API. This change will add all the labels corresponding to each container in the API response.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.07</mark></td><td>Previously, Prisma Cloud did not handle cases involving unaffected and patched Ruby version ranges correctly. Additionally, cases, where patched Ruby version ranges, were included within unaffected Ruby versions using the pessimistic version constraint (~>), those cases were also not handled correctly. This issue has been resolved.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.07</mark></td><td>Addressed the issue of false positives during vulnerability assessment due discrepancies between RPM package names and third-party package names where the same CVE may be listed under different names. For example, <code>urllib3</code> for Python versus <code>python3-urllib3</code> for RPM. This inconsistency led to potential false positives or missed vulnerabilities. In order to validate if the third-party package should be reported, Prisma Cloud now also assesses the origin package name.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.07</mark></td><td>Corrected parsing of Jenkins security information in affected versions and fix versions due to a scheme change. For example, the Jenkins Security Advisory 2021-10-06 did not produce fixed versions, showing all versions as vulnerable despite CVE-2014-3577 being fixed up to and including version 2.314.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.07</mark></td><td>Addressed an issue with Openshift cluster where incorrect image names were fetched for non RPM container images due to the cluster having a generic name for example, openshift-release-dev/ocp-v4.0-art-dev To resolve this. The mapping extracts the release and version from image labels and adjusts the name by combining registry, origin name, release, and version to be the image name. For example <code>&#x3C;registry>/&#x3C;image_name>:&#x3C;version>-&#x3C;release></code>.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.07</mark></td><td><p>Previously, Prisma Cloud skipped scanning Federal Information Processing Standards (FIPS)-enabled OpenSSL packages to avoid overriding older releases, and instead matched against non-FIPS versions. This led to inaccurate vulnerability reporting.</p><p>This issue has been fixed. Prisma Cloud now fully supports scanning FIPS-enabled OpenSSL versions, ensuring correct vulnerability detection and eliminating false positives.</p></td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.07</mark></td><td><p>Previously, errors encountered during image scans by Defender were not added to the console log.</p><p>This issue has been fixed. Now, when Defender scans images, error messages are printed to the console log along with the image ID and the name of the Defender.</p></td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.05</mark></td><td>Resolved issue causing containerized scans to fail due to long scan data, particularly when encountering large Java dependency lists. You can now conduct scans without encountering this issue.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.05</mark></td><td>With the transition to the CVE 5.0 dataset, NVD has updated the format of rejected CVE descriptions. Prisma Cloud now seamlessly identifies 'Rejected' and 'Disputed' statuses of CVEs. In NVD the status is <strong>now</strong> labeled as 'Rejected reason', while CVEs tagged as 'Disputed' are identified using <a href="http://cve.org/">cve.org</a> data source, ensuring accurate vulnerability assessment.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.05</mark></td><td>Previously, if modifications were done to a TAS application (such as renaming it), Defender failed to re-scan the application and update the results in the Console. This issue has been resolved. Defender now re-scans the TAS applications whenever changes are made to them.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.05</mark></td><td>Fix an issue where “risk factor” field was missed on Function and Host CSV results.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.05</mark></td><td>CVE-2023-6992 impacts the Cloudflare version of the zlib library. However, the zlib library included in Alpine Linux is not affected by this vulnerability. A formal <a href="https://gitlab.alpinelinux.org/alpine/aports/-/issues/15970">request</a> has been made to Alpine Linux to classify this CVE as a non-vulnerability for their zlib version. The necessary patch has been merged, and we anticipate its inclusion in the <a href="https://secdb.alpinelinux.org">Alpine Linux Security Database</a> soon.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.05</mark></td><td><p>Resolved parsing issues in vulnerable package versions.</p><p>The fix resolves the following issues related to detection of vulnerable package versions:</p><ul><li>Correct parsing of vulnerable package versions.</li><li>Parsing of version ranges with different prefixes.</li><li>Handling of conditions for multiple versions to ensure they are added to the Intelligence feed. This resolves both false negative and false positive alerts.</li></ul></td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.04</mark></td><td>Vulnerabilities identified as GHSA-xm99-6pv5-q363, also known as CVE-2022-29583, are now suppressed in Defender and Console images since they are disputed.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.04</mark></td><td>Fixed the error that blocked downloading of the serverless defender bundle for Azure C# functions.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.04</mark></td><td>Added the <code>incidentTime</code> macro for webhook alerts. The macro shows the time the incident occurred. For example, <code>Jan 21, 2018 UTC</code>. Go to <a href="https://docs.prismacloud.io/en/classic/compute-admin-guide/alerts/webhook">Alerts Webhook</a> to learn more about the macro.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.04</mark></td><td>Previously, node count was not appearing for EKS clusters on <strong>Manage > Cloud accounts</strong> as a part of <strong>Discovery</strong> report. This is now addressed, and the accurate node count is displayed both on the Prisma Cloud console and in <a href="https://pan.dev/prisma-cloud/api/cwpp/get-cloud-discovery/">API Cloud Discovery scan results</a>.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.04</mark></td><td>Resolved the issue where container images scanned with twistcli did not appear on the <strong>Runtime Security > Inventory > Assets</strong> and the <strong>Cloud Security > Inventory > Compute Workloads</strong> pages. <strong>Note:</strong> Use the <code>--build</code> and <code>--job</code> flags to include the build number and the job name to help identify the image as a build image that will be presented in the above screens.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.03</mark></td><td>Improved accuracy of information leakage detection that resolves some false positives.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.03</mark></td><td>Fixed twistcli tarball scan failing on hardlinks to symlinks without target files.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.03</mark></td><td>Fixed an issue with inconsistent CVE type and set the type to be “OS” and “Application”.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.03</mark></td><td>Fixed a filtering issue that excluded Ruby’s app and OS vulnerabilities during evaluation.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.03</mark></td><td>Fixed an issue that resulted in duplicate CVE records because of inconsistencies in the CPE list that is included in the RHEL feeds.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.03</mark></td><td>Fixed an issue that caused previous scan results of a failed registry scan to be removed.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.03</mark></td><td>The agentless scanner boot volume now enforces encryption by default.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.02</mark></td><td>Agentless scanning now supports scanning of Podman container images deployed to hosts with the default storage driver.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.02</mark></td><td>Fixed an issue where scanning scripts that contain binary data caused memory consumption issues.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.02</mark></td><td>Improved the detection of vulnerabilities on supported Windows OS workloads to fix false negative and false positive alerts related to Windows feeds.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.02</mark></td><td>Fixed an issue causing some TAS blobstore controllers not to be listed.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.02</mark></td><td>Fixed an issue found during configuration of the Tanzu blobstore scanner. The configuration didn’t filter the scanners from the selected cloud controller correctly. Now, when you provide a cloud controller in the Tanzu blobstore scan configuration, only the suitable scanners are available in the scanner dropdown.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.02</mark></td><td>Fixed an issue where users could not see credentials stored in the Runtime Security credential store, when creating a new System Admin role while specifying cloud accounts only onboarded under Runtime Security.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.02</mark></td><td>Added support for installing serverless defender on AWS with NodeJS runtime, using layer based deployment type and ES modules type.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.01</mark></td><td><strong>Container Support:</strong> Bump <code>github.com/containers/storage</code> to v1.42.0 (or later).</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.01</mark></td><td><strong>Documentation:</strong> Updated the inconsistent icons in the documentation of the trusted images compliance under <strong>Monitor > Compliance > Trusted images</strong>.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.01</mark></td><td><strong>Serverless:</strong> Fixed confusion around the serverless function defended status.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.01</mark></td><td><strong>Operating System Support:</strong> Fixed false positives caused by CVE-2016-9063 in hosts running RHEL.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.01</mark></td><td><strong>Operating System Support:</strong> Improve parsing of Debian feed for CVEs with status open to include only the vulnerable versions.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.01</mark></td><td><strong>Cloud Service Providers - Azure:</strong> Fixed an issue where the cluster name of Azure AKS clusters was incorrectly resolved by Defenders as vanilla Kubernetes cluster instead of AKS cluster, if the resource group name of the cluster contained the suffix <code>_group</code>.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.01</mark></td><td><strong>Image Scanning:</strong> Fixed an issue where system administrators could see all the clusters in the Image Vulnerability scan reports.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.01</mark></td><td><strong>Collections added using the Add a New Collection endpoint:</strong> Fixed the issue with collections that were added by invoking the <a href="https://pan.dev/prisma-cloud/api/cwpp/post-collections/">Add a New Collection</a> endpoint with one or more empty fields: such collections did not display in the Console. The Add a New Collection endpoint is updated to fix this issue. Now, all request body fields of this endpoint, except name, are optional. Any optional field that is not provided will default to the wildcard value '*'.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.01</mark></td><td><strong>Logging:</strong> Fixed an issue causing errors in logs after upgrading from v30.00.140 to v31.00.129.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.01</mark></td><td><strong>Registry Scanning:</strong> Fixed an issue that caused a scanning failure for Google artifactory registry using credentials imported from the Prisma Cloud platform.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.00</mark></td><td>Fixed an issue with agentless scanning that in some conditions failed scanning encrypted volumes when using hub mode in AWS.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.00</mark></td><td>In <code>v31.02.133</code>, the new 81 out-of-box admission control rules in Rego were not available by default. This is now fixed. With the v32.00 Console, you now get all the 81 OOB admission control rules.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.00</mark></td><td>Fixed an issue where "sourceType" field was missing for Splunk alert meesages. User can now add "sourceType" field to the custom alert JSON of Splunk and prisma cloud will define the external field based on the custom one.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.00</mark></td><td>Fixed an issue where the progress bar while scanning deployed images was not reported correctly.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.00</mark></td><td>Fixed an issue where Nuget vulnerabilities of same package with difference path appear with the same path.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.00</mark></td><td>Fixed an issue that stopped the registry scan due to an invalid credentials error. The registry scan now completes on credential fetch errors.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 32.00</mark></td><td>Custom rule names are now populated for runtime custom rule incidents. Also, labels are reported for when the incident occurred in a Kubernetes cluster.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 31.03.103</mark></td><td>Fixed an issue wherein the alerts were pending in the immediate alerts queue and causing logging errors.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 31.03.103</mark></td><td>Fixed an issue with a broken Jenkins CI link that incorrectly pointed to the Console with filter “true” and no relevant results. The Jenkins output log link now correctly shows the relevant filter for the Jenkins job under <strong>Monitor > Vulnerabilities > Images > CI</strong>.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 31.03.103</mark></td><td>Fixed an issue wherein the Tanzu apps were missing under <strong>Monitor > Vulnerabilities</strong> scan results for the deployed images on the Diego cells and the image scanning for TAS applications mounted on the external system took extremely long. To fix this issue, the Defender scan now ignores scanning the images of TAS applications mounted on the external file system.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 31.03.103</mark></td><td>Fixed a bug for AWS accounts configured to scan in hub mode. The bug caused a permissions error to appear in the UI during the cleanup stage, while no actual permissions issues were present and the scan was completed successfully.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 31.02.133</mark></td><td>Fixed issue in RHEL clusters running NodeOS where compliance checks didn’t show any non-compliant alerts.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 31.02.133</mark></td><td>Fixed an issue where Defender failed to block containers when containers were restarted frequently and generated too many audit events. This was fixed by decreasing the number of requests sent to the Console.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 31.02.133</mark></td><td>Fixed an issue where REST API requests triggered rate limiting after 23 requests in a 30 second interval. With this fix, the rate limit for Prisma Cloud Compute REST APIs is increased to 30 requests in 30 seconds.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 31.01.123</mark></td><td>Fixed an error in deploying and upgrading the Host Defenders on Windows Server 2019 installed on AWS.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 31.01.123</mark></td><td>Fixed an issue where node count was missing for EKS clusters under <strong>Manage > Cloud accounts</strong> cloud <strong>Discovery</strong> report. The correct node count is now displayed on the Console and in <a href="https://pan.dev/prisma-cloud/api/cwpp/get-cloud-discovery">API Cloud Discovery scan results</a>.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 31.00.129</mark></td><td>Fixed an issue limiting the support of Prisma Cloud Compute as a pluggable scanner in Harbor. The support is now extended to instances where the Defenders operate in a CRI environment.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 31.00.129</mark></td><td>Fixed an issue that caused missing version detection for jar packages when the version name included a date, for example, 20171018.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 31.00.129</mark></td><td>Fixed an issue preventing agentless scanning of onboarded Azure government accounts</td></tr><tr><td><mark style="background-color:orange;">Fixed in 31.00.129</mark></td><td>Fixed an issue caused when listing container details of containers on hosts using Docker as the CRI. The issue led to agentless scanning not discovering containers on the specified host. The fix improves the scan process tolerance to errors during the retrieval of containers metadata.</td></tr><tr><td><mark style="background-color:orange;">Fixed in 31.00.129</mark></td><td>Added missing OS labels, both <code>osDistro</code> and <code>osVersion</code>, to hosts scanned by agentless scanning.</td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-known-issues/known-fixed-issues.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
