On 21 Dec a vulnerability was reported to CrateDB regarding authentication that could potentially affect all users. We have taken immediate action to remediate and have posted details here: Disable trust of HTTP ``X-Real-IP`` header by default. The CrateDB team currently has no evidence that the issue was exploited or data inappropriately disclosed. Customers are encouraged to implement recommended mitigations while we continue to investigate and monitor the situation.
Related Posts
CrateDB Advisory #17278
2025-02-06CrateDB users should upgrade to 5.9.9, 5.8.6, or 5.7.6 to avoid a potential data loss issue that may occur when the maximum amount of shards per node limit has been changed.
CrateDB Achieves ISO 27001 Certification
2023-08-29We are thrilled to announce that CrateDB has earned the ISO/IEC 27001:2013 certification for its CrateDB Cloud SaaS offering on Azure and AWS. This remarkable achievement represents a major milestone ...
How We Use StackRox to Secure CrateDB Clusters on Docker
2017-10-11There are a number of safety issues when using containers. For example, many Docker images ship outdated libraries. And sometimes security vulnerabilities in these outdated libraries can lead to privi...