Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-12781

Опубликовано: 08 сент. 2023
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2023-12781: istio security update (IMPORTANT)

istio [1.16.7-1]

  • Addresses CVE CVE-2023-35941, CVE-2023-35942, CVE-2023-35943, CVE-2023-35944.

olcne [1.6.3-1]

  • Add Istio-1.16.7 to address CVE's
  • CVE-2023-35941
  • CVE-2023-35942
  • CVE-2023-35943
  • CVE-2023-35944

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

istio

1.16.7-1.el7

istio-istioctl

1.16.7-1.el7

olcne-agent

1.6.3-1.el7

olcne-api-server

1.6.3-1.el7

olcne-calico-chart

1.6.3-1.el7

olcne-gluster-chart

1.6.3-1.el7

olcne-grafana-chart

1.6.3-1.el7

olcne-istio-chart

1.6.3-1.el7

olcne-metallb-chart

1.6.3-1.el7

olcne-multus-chart

1.6.3-1.el7

olcne-nginx

1.6.3-1.el7

olcne-oci-ccm-chart

1.6.3-1.el7

olcne-olm-chart

1.6.3-1.el7

olcne-prometheus-chart

1.6.3-1.el7

olcne-utils

1.6.3-1.el7

olcnectl

1.6.3-1.el7

Связанные уязвимости

oracle-oval
около 2 лет назад

ELSA-2023-12780: istio security update (IMPORTANT)

oracle-oval
около 2 лет назад

ELSA-2023-12772: olcne security update (IMPORTANT)

oracle-oval
около 2 лет назад

ELSA-2023-12771: istio security update (IMPORTANT)

CVSS3: 7.5
redhat
около 2 лет назад

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12, the CORS filter will segfault and crash Envoy when the `origin` header is removed and deleted between `decodeHeaders`and `encodeHeaders`. Versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12 have a fix for this issue. As a workaround, do not remove the `origin` header in the Envoy configuration.

CVSS3: 6.3
nvd
около 2 лет назад

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12, the CORS filter will segfault and crash Envoy when the `origin` header is removed and deleted between `decodeHeaders`and `encodeHeaders`. Versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12 have a fix for this issue. As a workaround, do not remove the `origin` header in the Envoy configuration.