forked from istio/istio.io
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
[release-1.22] security adv, release notes 1.22.1 and 1.21.4 (istio#1…
…5358) (istio#15371) * release notes * Update content/en/news/releases/1.22.x/announcing-1.22.2/index.md * Update content/en/news/releases/1.21.x/announcing-1.21.4/index.md --------- Signed-off-by: Daniel Hawton <[email protected]> Co-authored-by: Faseela K <[email protected]>
- Loading branch information
Showing
6 changed files
with
117 additions
and
5 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -519,6 +519,7 @@ GCP_OPTS | |
gcr.io | ||
gdb | ||
Geneve | ||
GHSA-8mq4-c2v5-3h39 | ||
GiB | ||
git | ||
GitHub | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
33 changes: 33 additions & 0 deletions
33
content/en/news/releases/1.21.x/announcing-1.21.4/index.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,33 @@ | ||
--- | ||
title: Announcing Istio 1.21.4 | ||
linktitle: 1.21.4 | ||
subtitle: Patch Release | ||
description: Istio 1.21.4 patch release. | ||
publishdate: 2024-06-27 | ||
release: 1.21.4 | ||
--- | ||
|
||
This release implements the security updates described in our 27th of June post, [`ISTIO-SECURITY-2024-005`](/news/security/istio-security-2024-005) along with bug fixes to improve robustness. | ||
|
||
This release note describes what is different between Istio 1.21.3 and 1.21.4. | ||
|
||
{{< relnote >}} | ||
|
||
## Changes | ||
|
||
- **Added** `gateways.securityContext` to manifests to provide an option to customize the gateway `securityContext`. | ||
([Issue #49549](https://github.com/istio/istio/issues/49549)) | ||
|
||
- **Fixed** an issue where `istioctl analyze` returned IST0162 false positives. | ||
([Issue #51257](https://github.com/istio/istio/issues/51257)) | ||
|
||
- **Fixed** false positives in IST0128 and IST0129 when `credentialName` and `workloadSelector` were set. | ||
([Issue #51567](https://github.com/istio/istio/issues/51567)) | ||
|
||
- **Fixed** an issue where JWKS fetched from URIs were not updated promptly when there are errors fetching other URIs. | ||
([Issue #51636](https://github.com/istio/istio/issues/51636)) | ||
|
||
- **Fixed** 503 errors returned by `auto-passthrough` gateways created after enabling mTLS. | ||
|
||
- **Fixed** `serviceRegistry` ordering of the proxy labels, so we put the Kubernetes registry in front. | ||
([Issue #50968](https://github.com/istio/istio/issues/50968)) |
56 changes: 56 additions & 0 deletions
56
content/en/news/releases/1.22.x/announcing-1.22.2/index.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,56 @@ | ||
--- | ||
title: Announcing Istio 1.22.2 | ||
linktitle: 1.22.2 | ||
subtitle: Patch Release | ||
description: Istio 1.22.2 patch release. | ||
publishdate: 2024-06-27 | ||
release: 1.22.2 | ||
--- | ||
|
||
This release implements the security updates described in our 27th of June post, [`ISTIO-SECURITY-2024-005`](/news/security/istio-security-2024-005) along with bug fixes to improve robustness. | ||
|
||
This release note describes what is different between Istio 1.22.1 and 1.22.2. | ||
|
||
{{< relnote >}} | ||
|
||
## Changes | ||
|
||
- **Improved** waypoint proxies to no longer run as root. | ||
|
||
- **Added** `gateways.securityContext` to manifests to provide an option to customize the gateway `securityContext`. | ||
([Issue #49549](https://github.com/istio/istio/issues/49549)) | ||
|
||
- **Added** a new option in ztunnel to completely disable IPv6, to enable running on kernels with IPv6 disabled. | ||
|
||
- **Fixed** an issue where `istioctl analyze` returned IST0162 false positives. | ||
([Issue #51257](https://github.com/istio/istio/issues/51257)) | ||
|
||
- **Fixed** `ENABLE_ENHANCED_RESOURCE_SCOPING` not being part of helm compatibility profiles for Istio 1.20/1.21. | ||
([Issue #51399](https://github.com/istio/istio/issues/51399)) | ||
|
||
- **Fixed** Kubernetes job pod IPs may not be fully unenrolled from ambient despite being in a terminated state. | ||
|
||
- **Fixed** false positives in IST0128 and IST0129 when `credentialName` and `workloadSelector` were set. | ||
([Issue #51567](https://github.com/istio/istio/issues/51567)) | ||
|
||
- **Fixed** an issue where JWKS fetched from URIs were not updated promptly when there are errors fetching other URIs. | ||
([Issue #51636](https://github.com/istio/istio/issues/51636)) | ||
|
||
- **Fixed** an issue causing `workloadSelector` policies to apply to the wrong namespace in ztunnel. | ||
([Issue #51556](https://github.com/istio/istio/issues/51556)) | ||
|
||
- **Fixed** a bug causing `discoverySelectors` to accidentally filter out all `GatewayClasses`. | ||
|
||
- **Fixed** certificate chains parsing avoid unnecessary parsing errors by trimming unnecessary intermediate certificates. | ||
|
||
- **Fixed** a bug in ambient mode causing requests at the start of a Pod lifetime to be rejected with `unknown source`. | ||
|
||
- **Fixed** an issue in ztunnel where some expected connection terminations were reported as errors. | ||
|
||
- **Fixed** an issue in ztunnel when connecting to a service with a `targetPort` that exists only on a subset of pods. | ||
|
||
- **Fixed** an issue when deleting a `ServiceEntry` when there are duplicate hostnames across multiple `ServiceEntries`. | ||
|
||
- **Fixed** an issue where ztunnel would send directly to pods when connecting to a `LoadBalancer` IP, instead of going through the `LoadBalancer`. | ||
|
||
- **Fixed** an issue where ztunnel would send traffic to terminating pods. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,24 @@ | ||
--- | ||
title: ISTIO-SECURITY-2024-005 | ||
subtitle: Security Bulletin | ||
description: CVEs reported by Envoy. | ||
cves: [] | ||
cvss: "7.5" | ||
vector: "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" | ||
releases: ["1.21.0 to 1.21.3", "1.22.0 to 1.22.1"] | ||
publishdate: 2024-06-27 | ||
keywords: [CVE] | ||
skip_seealso: true | ||
--- | ||
|
||
{{< security_bulletin >}} | ||
|
||
## CVE | ||
|
||
### Envoy CVEs | ||
|
||
- __[GHSA-8mq4-c2v5-3h39](https://github.com/envoyproxy/envoy/security/advisories/GHSA-8mq4-c2v5-3h39)__: (CVSS Score 7.5, Moderate): Datadog: Datadog tracer does not handle trace headers with Unicode characters. | ||
|
||
## Am I Impacted? | ||
|
||
You are impacted if you are using Istio 1.21.0 to 1.21.3 or 1.22.0 to 1.22.1 and have enabled the Datadog tracer. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters