---
title: Security for Heartbleed vulnerability
source: https://docs.newrelic.com/docs/security/new-relic-security/security-bulletins/security-heartbleed-vulnerability
---

On April 7, 2014 the OpenSSL Project released an update to address a critical vulnerability known as [Heartbleed (CVE-2014-0160)](http://heartbleed.com). This vulnerability, which affects multiple sites across the Internet, could be remotely exploited to leak sensitive information.

## Action by New Relic [#nr-action]

New Relic has reviewed all of our sites and applications, and we have determined that the majority of our sites, including **[www.newrelic.com](http://www.newrelic.com)**, **rpm.newrelic.com**, and **insights.newrelic.com** are not vulnerable to this issue. New Relic did discover that the Documentation site (**docs.newrelic.com**) was vulnerable. This has now been patched, and the [SSL certificate](https://docs.newrelic.com/docs/accounts-partnerships/education/getting-started-new-relic/glossary#ssl-certificate) has been replaced.

## Change your password [#password]

New Relic has no evidence that any customer data (including user names and passwords) was exposed. However, if you have any concerns about your account's protection, you should change your password.

This procedure is for users who sign in directly to APM and do not have partner accounts or SAML SSO enabled accounts:

1.  Go to **[one.newrelic.com](https://one.newrelic.com) > [(user menu)](https://docs.newrelic.com/docs/accounts/accounts-billing/general-account-settings/intro-account-settings) > User preferences**.
2.  Type your **Current password**.
3.  Type your new **Password** (meeting [minimum requirements](https://docs.newrelic.com/docs/subscriptions/account-user-settings#requirements)), and then re-type the new password in **Password confirmation**.
4.  Select **Save user preferences**.
5.  **Regenerate** your [API key](https://docs.newrelic.com/docs/apis/rest-api-v2/requirements/api-keys#creating).

![screen user preferences.png](https://docs.newrelic.com/images/accounts_screenshot-full_user-preferences.webp "screen user preferences.png")

**[one.newrelic.com](https://one.newrelic.com) > [(user menu)](https://docs.newrelic.com/docs/accounts/accounts-billing/general-account-settings/intro-account-settings) > User preferences:** Anyone can change their own New Relic user name, account email, password, and other settings.
