Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:3335-1

Опубликовано: 22 сент. 2022
Источник: suse-cvrf

Описание

Security update for cdi-apiserver-container, cdi-cloner-container, cdi-controller-container, cdi-importer-container, cdi-operator-container, cdi-uploadproxy-container, cdi-uploadserver-container, containerized-data-importer

This update for cdi-apiserver-container, cdi-cloner-container, cdi-controller-container, cdi-importer-container, cdi-operator-container, cdi-uploadproxy-container, cdi-uploadserver-container, containerized-data-importer fixes the following issues:

Update to version 1.43.2

Security issues fixed:

  • CVE-2022-1996: Fixed CORS bypass in go-restful vendored dependency (bsc#1200528)

Other fixes:

  • Include additional tools used by cdi-importer: cdi-containerimage-server cdi-source-update-poller
  • Pack only cdi-{cr,operator}.yaml into the manifests RPM
  • Install tar package (used for cloning filesystem PVCs)

Список пакетов

SUSE Linux Enterprise Module for Containers 15 SP3
containerized-data-importer-manifests-1.43.2-150300.8.9.3
openSUSE Leap 15.3
containerized-data-importer-api-1.43.2-150300.8.9.3
containerized-data-importer-cloner-1.43.2-150300.8.9.3
containerized-data-importer-controller-1.43.2-150300.8.9.3
containerized-data-importer-importer-1.43.2-150300.8.9.3
containerized-data-importer-manifests-1.43.2-150300.8.9.3
containerized-data-importer-operator-1.43.2-150300.8.9.3
containerized-data-importer-uploadproxy-1.43.2-150300.8.9.3
containerized-data-importer-uploadserver-1.43.2-150300.8.9.3
obs-service-cdi_containers_meta-1.43.2-150300.8.9.3

Описание

Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.


Затронутые продукты
SUSE Linux Enterprise Module for Containers 15 SP3:containerized-data-importer-manifests-1.43.2-150300.8.9.3
openSUSE Leap 15.3:containerized-data-importer-api-1.43.2-150300.8.9.3
openSUSE Leap 15.3:containerized-data-importer-cloner-1.43.2-150300.8.9.3
openSUSE Leap 15.3:containerized-data-importer-controller-1.43.2-150300.8.9.3

Ссылки