Skip to content

Conversation

@theTibi
Copy link
Contributor

@theTibi theTibi commented Jan 6, 2026

  • Introduced a new alerting template for MongoDB CVE-2025-14847, which triggers alerts for vulnerable versions using Zlib compression.
  • Added a corresponding check configuration to monitor MongoDB instances for this vulnerability, including detailed descriptions and actions for remediation.
  • Both files include fixed versions and EOL information for affected MongoDB versions, enhancing security monitoring capabilities.

PMM-14685

Link to the Feature Build: SUBMODULES-4177

If this PR adds, removes or alters one or more API endpoints, please review and add or update the relevant API documentation as well:

  • API Docs updated

If this PR is related to some other PRs in this or other repositories, please provide links to those PRs:

  • Links to related pull requests (optional).

- Introduced a new alerting template for MongoDB CVE-2025-14847, which triggers alerts for vulnerable versions using Zlib compression.
- Added a corresponding check configuration to monitor MongoDB instances for this vulnerability, including detailed descriptions and actions for remediation.
- Both files include fixed versions and EOL information for affected MongoDB versions, enhancing security monitoring capabilities.
@theTibi theTibi requested a review from a team as a code owner January 6, 2026 14:44
@theTibi theTibi requested review from JiriCtvrtka and idoqo and removed request for a team January 6, 2026 14:44
…25_14847_zlib for consistency and clarity in naming conventions.
@codecov
Copy link

codecov bot commented Jan 6, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 45.98%. Comparing base (4088a94) to head (2663057).
⚠️ Report is 3 commits behind head on v3.

Additional details and impacted files
@@            Coverage Diff             @@
##               v3    #4888      +/-   ##
==========================================
- Coverage   45.98%   45.98%   -0.01%     
==========================================
  Files         365      365              
  Lines       38223    38223              
==========================================
- Hits        17578    17576       -2     
- Misses      18956    18957       +1     
- Partials     1689     1690       +1     
Flag Coverage Δ
managed 46.65% <ø> (-0.01%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

- Changed the severity level for alerts related to MongoDB CVE-2025-14847 from "error" to "warning" in the alerting template. This adjustment reflects a more appropriate response level for the identified vulnerabilities, allowing for better management of alerts without immediate escalation.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants