All systems are operational

Past Incidents

Thursday 9th July 2015

No incidents reported

Wednesday 8th July 2015

No incidents reported

Tuesday 7th July 2015

Network Magento patch required

SUPEE-6285

Magento has released a new security patch for versions 1.6 and newer, SUPEE-6285

The vulnerabilities

This bundle includes protection against the following security-related issues:

  • Customer Information Leak via RSS and Privilege Escalation
  • Request Forgery in Magento Connect Leads to Code Execution
  • Cross-site Scripting in Wishlist
  • Cross-site Scripting in Cart
  • Store Path Disclosure
  • Permissions on Log Files too Broad
  • Cross-site Scripting in Admin
  • Cross-site Scripting in Orders RSS

What you need to do

You must apply this new security patch as soon as possible. It can be downloaded from https://www.magentocommerce.com/download

You can either patch the store yourself using the instructions below, or submit a (chargeable) maintenance support ticket at https://www.theclientarea.info where our support team can apply the patch on your behalf (est. 5-10 mins application time).

More information

Read more about the patch here, http://us5.campaign-archive1.com/?u=34ff0d4b547cfa0a6a6901212&id=d47fcf1c6d

Monday 6th July 2015

Network Network Interruption

Unconfirmed connectivity issues reported.

  • Update (12:56): Some customers have reported connectivity issues to their stores. There is no known issue within the Sonassi internal or external network. We are currently investigating possible global internet issues (peripheral to Sonassi).
  • Update (13:15): We are unable to replicate any fault from any monitoring nodes, however we still conducting tests and collecting customer information.
  • Update (13:30): No further updates.
  • Update (13:45): Unable to reproduce this issue, we are still collecting information from customers to ascertain what the commonality is in requests (ie. a failing intermediary ISP). Investigations are still continuing.
  • Update (14:00): Issue deemed unreproducable/localised to an isolated group of customers. No further action will be taken. Fault downgraded from high to low.

Post-Mortem

Our report from the incident is as follows.

Issue

A very small number of customers reported connectivity issues, this was unreproduceable and unconfirmed by our network team.

Outage Length

No outage.

Underlying cause

We collected several traceroutes from customers, observing both the forward and reverse path to ascertain what commonality may have existed. However, no single cause could be identified

Symptoms

Customers reported slow page load times and general difficulty connecting to their stores.

Resolution

No action was taken by our team. We had 5 isolated reports from customers, which lead us to create a network alert in case of a network-wide event. It is our policy that after 5 isolated reports, we put out an un-confirmed notification whilst we investigate.

As we were unable to identify any fault, the issue can only be attributed to an unknown larger internet congestion issue.

Sunday 5th July 2015

No incidents reported

Saturday 4th July 2015

No incidents reported

Friday 3rd July 2015

No incidents reported