Security bulletins

This document contains important information regarding security vulnerabilities that could affect some versions of New Relic products. Security bulletins are a way for New Relic to let users know about security vulnerabilities, remediation strategies, and applicable updates for affected software.

You can register to receive notifications for future advisories.

2017 bulletins

Select the title of the vulnerability for more information.

Date Number Title Product Rating
2/9/2017 NR17-03 MongoDB aggregate queries not obfuscated Ruby agent Low
1/12/2017 NR17-02 Query parameters not removed from referer attribute in error trace .NET agent Medium
1/12/2017 NR17-01 Query parameters not removed from referer attribute in error trace Node.js agent Medium

Report security vulnerabilities to New Relic

New Relic is committed to the security of our customers and their data. We believe that responsible disclosure by security researchers and engaging with the security community is an important means of achieving our security goals.

If you believe you have found a security vulnerability in one of our products or websites, we welcome and greatly appreciate you reporting it to New Relic through one of these methods:

For more help

Additional documentation resources include:

If you need additional help, get support at support.newrelic.com.