Skip to content

Prowler

v5.33.1 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’
This release patches 2 known CVEs

Topics

aws azure cis-benchmark cloud cloudsecurity compliance
+12 more
cspm security forensics gcp gdpr hardening iam multi-cloud python security-audit security-hardening security-tools

Affected surfaces

auth rbac

Summary

AI summary

Broad release touches 🐞 Fixed, https://github.com/prowler-cloud/prowler/pull/11925, πŸ” Security, and πŸ”„ Changed.

Full changelog

UI

πŸ”„ Changed

  • RBAC role forms now explain Unlimited Visibility inside the Visibility section and keep the setting visible while group selection is hidden (#11890)

🐞 Fixed

  • CIS Level 1 and Level 2 compliance filters now match profiles prefixed with a license tier (e.g. "E3 Level 1"), so M365 CIS requirements are no longer hidden (#11924)
  • Jira dispatch polling now reports failed issue creation tasks instead of treating partial failures as successful (#11925)

API

🐞 Fixed

  • Session tokens are rejected after account password updates (#11914)
  • Jira dispatch task results now surface user-facing Jira failure messages (#11925)
  • AWS Attack Paths privilege escalation queries no longer fail on Neo4j with Aggregation column contains implicit grouping expressions (#11939)

πŸ” Security

  • OpenAI-compatible Lighthouse provider base URLs are restricted before connection checks (#11940)
  • LIGHTHOUSE_AI_OPENAI_COMPATIBLE_ALLOWED_HOSTS environment variable to allow internal hosts as OpenAI-compatible Lighthouse AI base URLs (#11942)

SDK

🐞 Fixed

  • ECS task definition resource limits now select the latest task definitions by registration date instead of relying on ARN ordering (#11891)
  • dlm_ebs_snapshot_lifecycle_policy_exists no longer initializes the full EC2 inventory just to detect EBS snapshots, avoiding slow scans when checking DLM lifecycle policies (#11900)
  • dms_instance_no_public_access no longer initializes the full EC2 service when there are no DMS replication instances (#11902)
  • organizations_scp_check_deny_regions no longer reports false FAIL for AWS Organizations that restrict regions with Allow-based SCPs; the Allow path now checks the statement Effect instead of an always-false comparison that made it unreachable (#11915)
  • Jira issue creation failures now preserve safe structured response details from Jira (#11925)
  • Azure Function App optional permission failures now log as warnings, and Function App environment variable fields use the correct spelling internally (#11926)

Security Fixes

  • Session tokens are rejected after account password updates (prevents token reuse)
  • OpenAI‑compatible Lighthouse provider base URLs are now restricted before connection checks

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Prowler

Get notified when new releases ship.

Sign up free

About Prowler

Tool based on AWS-CLI commands for Amazon Web Services account security assessment and hardening.

All releases β†’

Related context

Earlier breaking changes

  • v5.34.0 Renames UI integration enable flags to past tense (e.g., UI_SENTRY_ENABLE β†’ UI_SENTRY_ENABLED).

Beta — feedback welcome: [email protected]