Friday, October 22, 2021

Critical Security Issue - Discourse: Remote Code Execution via Malicious SNS Subscription Payload

A validation bug in the upstream aws-sdk-sns Ruby gem can lead to Remote Code Execution (RCE) in Discourse via a maliciously crafted request, see CVE-2021-41162.

The following are the versions affected by this bug: 

  • stable: 2.7.8
  • beta: 2.8.0.beta6
  • tests-passed: 2.8.0.beta6

The Bitnami team already released a new version of Discourse for all the supported platforms: virtual machine, cloud image, container, and Helm Charts.

Update your deployments to run any of the following versions:

  •  stable: 2.7.9
  •  beta: 2.8.0.beta7
  •  tests-passed: 2.8.0.beta7

Please refer to the following Security Advisory to learn more. 

VMware Marketplace Launches Third-Party Commerce Capability

Originally published on VMware Tech Alliance Partners (TAP) Blog

Authored by Ajay Patel

VMware users can now purchase third-party partner solutions from the VMware Marketplace and deploy these solutions directly to VMware endpoints. Plus, we are delighted to announce a host of upcoming VMware Marketplace portfolio capabilities and services that will accelerate our customers’ cloud adoption journeys and our partners’ go-to-market strategies with VMware.

Recent innovations in digitization have had deep impacts in almost every aspect of our life, from food and healthcare to personal finance and manufacturing. Core to this are innovative IT applications that are more intelligent and powerful than ever before. In part, this is fueled by the wide gamut of tools available to build applications, and the breadth available in multi-cloud computing infrastructure to run these applications. Hence, it is vital for organizations across all industries to empower their development and technology teams with access to the most expansive software tool set to build, run and manage these applications. All actors across the stack, from IT Administrators to DevOps Engineers, to Developers, and Business users, need easy and quick access to the tools to innovate quickly, build effectively and manage efficiently.

The need for an accessible ecosystem

At VMware, we seek to empower our users by giving them the ability to choose the right set of tools for their unique goals. We build deep, meaningful partnerships with industry peers to support our customers’ choices across their full technology stacks. We also make the discovery and usage of these partner solutions simpler through the VMware Marketplace. The VMware Marketplace is that one-stop shop – with over 2,100 solutions spanning categories such as security, storage, networking and more, where customers can discover and deploy validated and certified ecosystem solutions for all VMware products.

Discover, try, buy, deploy

Today, we are proud to announce the launch of commercial capabilities on VMware Marketplace – making it the single location to discover, try, purchase, and deploy VMware ecosystem solutions!

We launched the initial phase of our commercial transactability journey with our design partners at Catchpoint, LicenseFortress, and One Convergence.

In future phases, we plan to expand our commerce capabilities to include other forms of payments and offer types including pay by invoice, credit fund based transactions and usage based billing.

Easing our customer’s digital innovation journey

The VMware Marketplace houses a robust catalog of validated and certified artifacts and images that assures users of interoperability with their choice of VMware platform. VMware Marketplace reduces customer consumption friction, through its easy filter / search functionality and an in-product experience with various VMware products (for example, the VMware Cloud Director App Launchpad).

With the addition of commerce, VMware Marketplace further smoothens that customer journey. Users can discover the right ecosystem solution, try it out, purchase it directly if they are satisfied with the trial, and then deploy that file directly to vSphere or other VMware locations – without ever leaving the Marketplace user interface.

And that’s not all

Apart from this keystone commercial capability, we also announced a few exciting forthcoming capabilities at VMworld 2021:

  • We plan to launch image building capabilities, that will enable any user – whether a VMware customer or a VMware partner – to provide us with code or a package that we can build, package, verify, customize, and publish for them in the format of their choice and deployable on the platform of their choice.
  • We plan to enable deployments of solutions directly from VMware Marketplace to native cloud endpoints such as AWS, Azure and Google Cloud Platform by packaging solutions in the applicable formats (for example, Amazon Machine Images (AMIs) for AWS).
  • We intend to launch VMware Application Catalog that expands on the capability of Tanzu Application Catalog and enables curation and customization of VM-based images in addition to container images supported today.

Together, these changes will provide our customers with the ability to create a curated catalog of open source, ISV content and their own private images that are compatible with the cloud of their choice.

Next steps

If you are a VMware ecosystem partner and would like to enable sales of your solution through VMware Marketplace, please contact us at VMwareMarketplace@vmware.com.

If you would like to publish a paid listing on VMware Marketplace, please contact us at VMwareMarketplace@vmware.com. If you’d like to start purchasing through VMware Marketplace, head to our catalog page! To learn more about VMware Marketplace, please visit our webpage.

Thursday, September 30, 2021

The Bitnami Helm charts and Containers Catalog is Growing!

The Bitnami Application Catalog grows every month to offer to both our catalog users and our enterprise users new Helm charts and containers to help shorten the builder’s journey for running applications in production. 

In the last 4 months, we have added more than 15 new solutions to our catalog. Additionally, delivering on our community promise, the Bitnami content team has merged more than 300 pull requests (approximately 60% of them from external contributors) and closed almost the same number of user issues.   

As always, community feedback and external contributions are essential for us to improve our solutions based on the user experience. 

Along with these new additions, we have also incorporated in the catalog two Data Platform blueprints implemented via Helm charts. 

Find in the list below the new Helm charts and containers available for you to discover. 

Bitnami Helm charts Releases (Jun - Sep 2021) 

Bitnami Containers Releases (Jun - Sep 2021) 

Data Platform Blueprints for Deployment Automation

Bitnami has added to its catalogs two data platform blueprints in the form of Helm charts specifically designed for enabling enterprise development teams to automate the deployment of multi-stacks data platforms on Kubernetes:  

Data Platform Blueprint 1 with Kafka-Spark-Solr  

Data Platform Blueprint 2 with Kafka-Spark-Elasticsearch  

The use of blueprints reduces the need for reconfigurations after initial data platform deployments. These Helm charts have pre-defined parameters to automate the deployment lifecycle. This default configuration covers:  

  • Pod placement rules 
  • Pod resource sizing rules 
  • Default settings to ensure Pod access security 
  • Optional Tanzu Observability framework configuration 

To learn how to use Bitnami deployment blueprints to simplify the complexity of new data analytics platform deployment, check out this series of tutorials.  

Support and Resources 

Refer to the Bitnami documentation and our Tutorials site to learn more about Kubernetes and Bitnami Helm charts and containers. 

For solving the problems you may have (including deployment support, operational support, and bug fixes), please open an issue in the Bitnami Helm chart GitHub repository.  Also, if you want to contribute to the catalog, feel free to send us a pull request, and the team will check it and guide you in the process for a successful merge.   

Visit the Bitnami Helm chart repository in GitHub for more information about our charts’ latest releases and improvements or navigate to the Bitnami Application Catalog and VMware Marketplace for deploying the solution of your choice in any Kubernetes platform. 

Bitnami Helm charts are also available for deployment via Kubeapps installation.