Skip to content

Commit

Permalink
Merge branch 'main' into main
Browse files Browse the repository at this point in the history
  • Loading branch information
DGovEnterprise authored Apr 30, 2024
2 parents 7789a71 + ad4d5c1 commit 48c54e8
Show file tree
Hide file tree
Showing 2 changed files with 26 additions and 1 deletion.
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
# R Programming Language Vulnerability - 20240430003

## Overview

A severe security vulnerability in the R programming language has been disclosed, which could be exploited by malicious actors to create a malicious RDS (R Data Serialization) file that results in arbitrary code execution when loaded and referenced.

## What is vulnerable?

| Product Affected | CVE | Severity | CVSS |
| ---------------------------------------------- | ----------------------------------------------------------------- | -------- | ---- |
| The R Project <br> All versions prior to 4.4.0 | [CVE-2024-27322](https://nvd.nist.gov/vuln/detail/CVE-2024-27322) | **High** | 8.8 |

## What has been observed?

There is no evidence of exploitation affecting Western Australian Government networks at the time of publishing.

## Recommendation

The WA SOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframe of *one month...* (refer [Patch Management](../guidelines/patch-management.md)):

## Additional References

- [NVD - CVE-2024-27322 (nist.gov)](https://nvd.nist.gov/vuln/detail/CVE-2024-27322)
- [Newly Discovered R Programming Language Vulnerability Could Lead to Supply Chain Attacks - VULNERA](https://vulnera.com/newswire/newly-discovered-r-programming-language-vulnerability-could-lead-to-supply-chain-attacks/)
- [R Programming Language Exploit(zerosecurity.org)](https://zerosecurity.org/2024/04/r-programming-language-cve-2024-27322-allows-arbitrary-code-execution/)
2 changes: 1 addition & 1 deletion docs/guidelines/secure-configuration.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
![image](https://github.com/wagov/wasocshared/assets/121014/581293d3-2ced-4929-9059-90c84608a8b0)# Secure Configuration Assessment Guideline
# Secure Configuration Assessment Guideline

This guideline is intended to define a simple approach to ongoing monitoring and assurance of secure configuration of common tools and platforms.

Expand Down

0 comments on commit 48c54e8

Please sign in to comment.