Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2019-4717

Опубликовано: 29 июл. 2019
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2019-4717: kubeadm-ha-setup security update (IMPORTANT)

[0.0.2-1.0.52]

  • [OLCNE-678] Restore fails when trying to restore after a failed update

[0.0.2-1.0.51]

  • [OLCNE-667] Minor version update doesn't update kubeadm on all master nodes

[0.0.2-1.0.50]

  • Make k8s 1.14 specific changes

[0.0.2-1.0.49]

  • [OLCNE-668] Remove 1.10 and 1.11 version since they are incompatable

[0.0.2-1.0.48]

  • [OLCNE-549] Support deploying 5 master nodes

[0.0.2-1.0.47]

  • Only update/upgrade the controlplane images if they changed in the Release object

[0.0.2-1.0.46]

  • [OLCNE-571] Fix version comparison function during upgrade

[0.0.2-1.0.45]

  • Fix rpm version compare
  • [OLCNE-550] Allow kubernetes updates for patch version

[0.0.2-1.0.44]

  • [OLCNE-528] Allow assume yes to deploy a single master without the prompt

[0.0.2-1.0.43]

  • [OLCNE-524] Post cluster creation should check only for master nodes

[0.0.2-1.0.42]

  • [OLCNE-335] Update keepalived check api server to ensure we are grepping the correct IP

[0.0.2-1.0.41]

  • [OLCNE-470] Make ha.yaml an optional argument in the cli for single master cluster

[0.0.2-1.0.40]

  • [OLCNE-486] Add pod cidr default and refactor ha.yaml example

[0.0.2-1.0.39]

  • [OLCNE-313] Remove features: feature1_13=true from config

[0.0.2-1.0.38]

  • Default kubernetes version to latest production version

[0.0.2-1.0.37]

  • [OLCNE-411] Fix keepalived issue when firewalld is disable

[0.0.2-1.0.36]

  • Default kubernetes version to latest production version

[0.0.2-1.0.35]

  • Add addons template and config files

[0.0.2-1.0.34]

  • Enhance tests

[0.0.2-1.0.33]

  • fix regression of previous firewall fix

[0.0.2-1.0.32]

  • Fix firewall issues during restore [ OLCNE 343 ]

[0.0.2-1.0.31]

  • Fix firewall issues [ OLCNE 249, 262 ]

[0.0.2-1.0.30]

  • Enhance output while validating the system

[0.0.2-1.0.29]

  • [OLCNE-85] Fix DR in 1.13

[0.0.2-1.0.28]

  • Fix apiserver_cert_extra_sans for 1.13 clusters

[0.0.2-1.0.27]

  • Fix update/upgrade output message

[0.0.2-1.0.26]

  • Fix major upgrade

[0.0.2-1.0.25]

  • Add registry migration

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

kubeadm-ha-setup

0.0.2-1.0.52.el7

Связанные CVE

Связанные уязвимости

CVSS3: 3.3
redhat
около 6 лет назад

In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to other users/groups, the written files may be modified by other users/groups and disrupt the kubectl invocation.

CVSS3: 5
nvd
около 6 лет назад

In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to other users/groups, the written files may be modified by other users/groups and disrupt the kubectl invocation.

CVSS3: 5
debian
около 6 лет назад

In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the ...

CVSS3: 5
github
больше 3 лет назад

Kubernetes Unsafe Cacheing

oracle-oval
почти 6 лет назад

ELSA-2019-4716: kubernetes security update (IMPORTANT)