Описание
Security update for cdi-apiserver-container, cdi-cloner-container, cdi-controller-container, cdi-importer-container, cdi-operator-container, cdi-uploadproxy-container, cdi-uploadserver-container, containerized-data-importer
This update for cdi-apiserver-container, cdi-cloner-container, cdi-controller-container, cdi-importer-container, cdi-operator-container, cdi-uploadproxy-container, cdi-uploadserver-container, containerized-data-importer fixes the following issues:
Update to version 1.43.2
Security issues fixed:
- CVE-2022-1996: Fixed CORS bypass in go-restful vendored dependency (bsc#1200528)
Other fixes:
- Include additional tools used by cdi-importer: cdi-containerimage-server cdi-source-update-poller
- Pack only cdi-{cr,operator}.yaml into the manifests RPM
- Install tar package (used for cloning filesystem PVCs)
Список пакетов
SUSE Linux Enterprise Module for Containers 15 SP3
containerized-data-importer-manifests-1.43.2-150300.8.9.3
openSUSE Leap 15.3
containerized-data-importer-api-1.43.2-150300.8.9.3
containerized-data-importer-cloner-1.43.2-150300.8.9.3
containerized-data-importer-controller-1.43.2-150300.8.9.3
containerized-data-importer-importer-1.43.2-150300.8.9.3
containerized-data-importer-manifests-1.43.2-150300.8.9.3
containerized-data-importer-operator-1.43.2-150300.8.9.3
containerized-data-importer-uploadproxy-1.43.2-150300.8.9.3
containerized-data-importer-uploadserver-1.43.2-150300.8.9.3
obs-service-cdi_containers_meta-1.43.2-150300.8.9.3
Ссылки
- Link for SUSE-SU-2022:3335-1
- E-Mail link for SUSE-SU-2022:3335-1
- SUSE Security Ratings
- SUSE Bug 1200528
- SUSE CVE CVE-2022-1996 page
Описание
Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.
Затронутые продукты
SUSE Linux Enterprise Module for Containers 15 SP3:containerized-data-importer-manifests-1.43.2-150300.8.9.3
openSUSE Leap 15.3:containerized-data-importer-api-1.43.2-150300.8.9.3
openSUSE Leap 15.3:containerized-data-importer-cloner-1.43.2-150300.8.9.3
openSUSE Leap 15.3:containerized-data-importer-controller-1.43.2-150300.8.9.3
Ссылки
- CVE-2022-1996
- SUSE Bug 1200528