OLVM 4.5 vulnerability
after upgrading the OLVM cluster from version 4.4 to 4.5, a critical vulnerability was identified on the self-hosted engine ports as below and attached scan report.
Python Unsupported Version Detection on ports 6100, 9696 and 35357
also a medium vulnerability was identified on the self-hosted engine and KVM ports as the below and attached scan report
- Web Server Generic Cookie Injection on ports 54322 and 54323
- HSTS Missing From HTTPS Server (RFC 6797) on ports 54322, 54323, 443, 6100, 9696 and 35357
- SSL Self-Signed Certificate on ports 443, 54321, 54322, 54323, 6641 and 6642
- SSL Certificate Cannot Be Trusted on ports 443, 54321, 54322, 54323, 6641, 6642, 9696, 35357 and 16514
regarding the ssl certificate on ports should we dismiss it as a false positive or replace the internal certificate with on ssl certificate from CA authorities please advice on the process.