Описание
ELSA-2019-4816: kubernetes security update (IMPORTANT)
kubernetes [1.12.10-1.0.10]
- [CVE-2019-16276] Kubernetes Vulnerabilities Allow Authentication Bypass, DoS
[1.12.10-1.0.9]
- Define rolling update for flannel
[1.12.10-1.0.8]
- Modify flannel/dashboard image tags to use images that have the cve fix
kubeadm-ha-setup [0.0.2-1.0.68]
- Pull image prior to update and fix image repo for addons
[0.0.2-1.0.67]
- Bump golang build version
[0.0.2-1.0.66]
- [CVE-2019-16276] Support patching flannel/dashboard on upgrade
[0.0.2-1.0.65]
- [CVE 2019-16276] Support deploygin 1.12 and 1.13 with CVE patched
[0.0.2-1.0.64]
- [CVE-2019-16276] Support patching etcd on upgrade
[0.0.2-1.0.63]
- [CVE-2019-16276] while upgrading a cluster patch the coredns image
[0.0.2-1.0.62]
- CVE-2019-16276 : Update flannel , etcd coredns and dashboard images.
[0.0.2-1.0.61]
- Added Support for 1.13.11 and removed support for 1.13.10
[0.0.2-1.0.59]
- Remove Support for 1.14.6
[0.0.2-1.0.58]
- Replacing reference to kubernetes-dashboard-amd64 with kubernetes-dashboard
[0.0.2-1.0.57]
- Support 1.12.10
[0.0.2-1.0.56]
- Support 1.14.6
[0.0.2-1.0.55]
- Support 1.13.10
[0.0.2-1.0.54]
- Support 1.13.9
Обновленные пакеты
Oracle Linux 7
Oracle Linux x86_64
kubeadm
1.12.10-1.0.10.el7
kubeadm-ha-setup
0.0.2-1.0.68.el7
kubeadm-upgrade
0.0.1-1.0.27.el7
kubectl
1.12.10-1.0.10.el7
kubelet
1.12.10-1.0.10.el7
Ссылки на источники
Связанные уязвимости
In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to other users/groups, the written files may be modified by other users/groups and disrupt the kubectl invocation.
In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to other users/groups, the written files may be modified by other users/groups and disrupt the kubectl invocation.
In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the ...
ELSA-2019-4717: kubeadm-ha-setup security update (IMPORTANT)