Add note regarding rancher pentest reports public availability (#961)

* Add note regarding rancher pentest reports public availability

This PR will add a note regarding third-party penetration test reports
public disclosure.

* Update docs/pages-for-subheaders/rancher-security.md

* versioning for 2.7, 2.8

* added back in webhook material at end of 2.8 page

* corrected broken link

---------

Co-authored-by: Pietro Dell'Amore <pdellamore@MacBook-Pro-de-Pietro.local>
Co-authored-by: Marty Hernandez Avedon <marty.avedon@suse.com>
This commit is contained in:
pdellamore
2023-10-26 19:05:22 -04:00
committed by GitHub
co-authored by Pietro Dell'Amore Marty Hernandez Avedon
parent 74d684f77b
commit 01c0d1503c
3 changed files with 10 additions and 4 deletions
@@ -73,13 +73,15 @@ Each version of Rancher's self-assessment guide corresponds to specific versions
### Third-party Penetration Test Reports
Rancher periodically hires third parties to perform security audits and penetration tests of the Rancher 2.x software stack. The environments under test follow the Rancher provided hardening guides at the time of the testing. Previous penetration test reports are available below.
Rancher periodically hires third parties to perform security audits and penetration tests of the Rancher software stack. The environments under test follow the Rancher provided hardening guides at the time of the testing. Previous penetration test reports are available below.
Results:
- [Cure53 Pen Test - July 2019](https://releases.rancher.com/documents/security/pen-tests/2019/RAN-01-cure53-report.final.pdf)
- [Untamed Theory Pen Test - March 2019](https://releases.rancher.com/documents/security/pen-tests/2019/UntamedTheory-Rancher_SecurityAssessment-20190712_v5.pdf)
Please note that new reports are no longer shared or made publicly available.
### Rancher Security Advisories and CVEs
Rancher is committed to informing the community of security issues in our products. For the list of CVEs (Common Vulnerabilities and Exposures) for issues we have resolved, refer to [this page.](../reference-guides/rancher-security/security-advisories-and-cves.md)
@@ -94,4 +96,4 @@ For recommendations on securing your Rancher Manager deployments, refer to the [
### Rancher Webhook Hardening
The Rancher webhook deploys on both the upstream Rancher cluster and all provisioned clusters. For recommendations on hardening the Rancher webhook, see the [Hardening the Rancher Webhook](../reference-guides/rancher-security/rancher-webhook-hardening.md) guide.
The Rancher webhook deploys on both the upstream Rancher cluster and all provisioned clusters. For recommendations on hardening the Rancher webhook, see the [Hardening the Rancher Webhook](../reference-guides/rancher-security/rancher-webhook-hardening.md) guide.