Until a patched version is available, the safest option is to run the Rust-based deployment path and restrict network access to the ChromaDB port to trusted clients only.
Worth noting the failure of Chroma to respond to these findings since February!
1 Like
Not responding to a critical CVE for 2 months, and the ISAC? Yikes.
It’s unfortunate these aren’t tracked better, since this is actually what I want from Bitsight.
Every GRC team at these Enterprises plastered across their site should be keen on this timeline.