Published · 5h agoSecurity2 min read
Five Cisco 10.0s, and no advisory: what the supplied documents actually say
The rail card promised five perfect CVSS scores. The two documents on this desk are a Secure Workload policy guide and GitLab's incident runbook, and neither names a CVE.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- One supplied source is the Cisco Secure Workload User Guide On-Premises, Release 3.9, section 'Manage Policy Lifecycle in Secure Workload', published on cisco.com.
- In Cisco Secure Workload, a cluster is a set of workloads grouped together within a workspace, and automatic policy discovery groups workloads into clusters based on the signals observed in the timeframe specified during the run configuration.
- Cluster queries are dynamic unless defined with specific IP addresses; with dynamic queries cluster membership changes to reflect inventory, so a query based on a hostname containing 'HR' automatically includes additional HR hosts as they are added.
- Only workloads that are not already members of a manually approved cluster in the relevant workspace are affected by subsequent policy discovery.
- Clusters promoted to inventory filters are not changed during subsequent policy discovery, and unlike clusters, inventory filters are not tied to a workspace but are globally available within the Secure Workload deployment.
Compiled by The WatchSomething wrong?How this is made
Why it matters
A perfect CVSS score is a claim about reachability and impact, and it becomes work only when it arrives with an identifier and a list of affected release trains. Neither is here. The Cisco document supplied to this desk explains how automatic policy discovery groups workloads into clusters from signals observed in a timeframe set by the run configuration [2], not what an attacker can do to the product.
That guide is still worth an hour in a week when patching is blocked, for one detail. Cluster queries are dynamic unless you pin them to specific IP addresses, so a query written against a hostname substring takes in matching hosts as they are added [3]. Segmentation that enrols new machines on its own is a containment boundary; segmentation pinned to addresses is a snapshot of the day you wrote it.
On the GitLab side, the runbook enumerates what tends to leak: passwords, personal, group and project access tokens, runner tokens, pipeline trigger tokens and SSH keys [8]. Its response steps are clerical and that is the point. Record the time the credential was exposed and the time it was revoked, then work the audit log for newly created users, new tokens, malicious pipelines and changes to code or project settings [10].
The figure at the top of the card is not in either document [13]. We are not going to reconstruct five CVE numbers from memory. A citation to an advisory nobody supplied is worse than a blank, because a blank does not send anyone patching the wrong train.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
One supplied source is the Cisco Secure Workload User Guide On-Premises, Release 3.9, section 'Manage Policy Lifecycle in Secure Workload', published on cisco.com.
ReportedView cited source - [2]
In Cisco Secure Workload, a cluster is a set of workloads grouped together within a workspace, and automatic policy discovery groups workloads into clusters based on the signals observed in the timeframe specified during the run configuration.
ReportedView cited source - [3]
Cluster queries are dynamic unless defined with specific IP addresses; with dynamic queries cluster membership changes to reflect inventory, so a query based on a hostname containing 'HR' automatically includes additional HR hosts as they are added.
ReportedView cited source - [4]
Only workloads that are not already members of a manually approved cluster in the relevant workspace are affected by subsequent policy discovery.
ReportedView cited source - [5]
Clusters promoted to inventory filters are not changed during subsequent policy discovery, and unlike clusters, inventory filters are not tied to a workspace but are globally available within the Secure Workload deployment.
ReportedView cited source - [7]
The other supplied source is GitLab Docs 'Responding to security incidents', created by the GitLab Security Operations team for administrators and maintainers of GitLab Self-Managed instances and groups on GitLab.com, as a supplement to an organisation's own processes.
ReportedView cited source
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- docs.gitlab.com5h agoResponding to security incidents | GitLab Docs


