Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:3334-1

Опубликовано: 22 сент. 2022
Источник: suse-cvrf

Описание

Security update for cdi-apiserver-container, cdi-cloner-container, cdi-controller-container, cdi-importer-container, cdi-operator-container, cdi-uploadproxy-container, cdi-uploadserver-container, containerized-data-importer

This update for cdi-apiserver-container, cdi-cloner-container, cdi-controller-container, cdi-importer-container, cdi-operator-container, cdi-uploadproxy-container, cdi-uploadserver-container, containerized-data-importer fixes the following issues:

Update to version 1.51.0

Security issues fixed in vendored dependencies:

  • CVE-2022-1996: Fixed CORS bypass (bsc#1200528)

  • Include additional tools used by cdi-importer: cdi-containerimage-server cdi-image-size-detection cdi-source-update-poller

  • Pack only cdi-operator and cdi-cr release manifests

  • Install tar for cloning filesystem PVCs

Список пакетов

SUSE Linux Enterprise Module for Containers 15 SP4
containerized-data-importer-manifests-1.51.0-150400.4.3.1
openSUSE Leap 15.4
containerized-data-importer-api-1.51.0-150400.4.3.1
containerized-data-importer-cloner-1.51.0-150400.4.3.1
containerized-data-importer-controller-1.51.0-150400.4.3.1
containerized-data-importer-importer-1.51.0-150400.4.3.1
containerized-data-importer-manifests-1.51.0-150400.4.3.1
containerized-data-importer-operator-1.51.0-150400.4.3.1
containerized-data-importer-uploadproxy-1.51.0-150400.4.3.1
containerized-data-importer-uploadserver-1.51.0-150400.4.3.1
obs-service-cdi_containers_meta-1.51.0-150400.4.3.1

Описание

Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.


Затронутые продукты
SUSE Linux Enterprise Module for Containers 15 SP4:containerized-data-importer-manifests-1.51.0-150400.4.3.1
openSUSE Leap 15.4:containerized-data-importer-api-1.51.0-150400.4.3.1
openSUSE Leap 15.4:containerized-data-importer-cloner-1.51.0-150400.4.3.1
openSUSE Leap 15.4:containerized-data-importer-controller-1.51.0-150400.4.3.1

Ссылки