Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerabilities found in Gloo version 1.17.0 #10095

Open
DreyfussDaena opened this issue Sep 24, 2024 · 2 comments
Open

Vulnerabilities found in Gloo version 1.17.0 #10095

DreyfussDaena opened this issue Sep 24, 2024 · 2 comments
Labels
Area: Envoy activities related to envoy proxy Type: Bug Something isn't working

Comments

@DreyfussDaena
Copy link

Gloo Edge Product

Enterprise

Gloo Edge Version

gloo-ee-1.17.x

Kubernetes Version

v1.28.6

Describe the bug

Our security scans have found a new vulnerability.
https://security-tracker.debian.org/tracker/CVE-2024-7207
There is a fix in versions 1.31.2, 1.30.6, 1.29.9, 1.28.7
See:
GHSA-ffhv-fvxq-r6mf

Expected Behavior

This vulnerability should be resolved asap as it is very high and could cause potential security issues.
A new version of gloo-ee-1.17.x should be released - please update us as soon as this issues is fixed and we will consume it.

Steps to reproduce the bug

These vulnerabilities came up on a BlackDuck scan while scanning the gloo images.

Additional Environment Detail

No response

Additional Context

No response

@DreyfussDaena DreyfussDaena added the Type: Bug Something isn't working label Sep 24, 2024
@DuncanDoyle
Copy link
Contributor

Envoy bump to 1.30.6 is planned for Gloo Gateway 1.17.3, which will be released shortly: https://github.com/solo-io/solo-projects/issues/6934

@DuncanDoyle DuncanDoyle added the Area: Envoy activities related to envoy proxy label Sep 24, 2024
@DreyfussDaena
Copy link
Author

Please update with status,
Thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Area: Envoy activities related to envoy proxy Type: Bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants