Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependency pomerium/ingress-controller to v0.26.1 #13

Merged
merged 1 commit into from
Jul 16, 2024

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented May 18, 2024

Mend Renovate

This PR contains the following updates:

Package Type Update Change
pomerium/ingress-controller Kustomization minor v0.25.2 -> v0.26.1
pomerium/ingress-controller minor v0.25.2 -> v0.26.1

Release Notes

pomerium/ingress-controller (pomerium/ingress-controller)

v0.26.1

Compare Source

Security

This release includes multiple security updates:

  • The Pomerium user info page (at /.pomerium) unintentionally included serialized OAuth2 access and ID tokens from the logged-in user's session. These tokens are not intended to be exposed to end users, and have now been removed. CVE-2024-39315

    Credit to Vadim Sheydaev, aka Enr1g for reporting this issue.

  • This release also includes an update from Envoy 1.30.1 to Envoy 1.30.3 to address multiple security issues:

    • CVE-2024-34362: Crash (use-after-free) in EnvoyQuicServerStream
    • CVE-2024-34363: Crash due to uncaught nlohmann JSON exception
    • CVE-2024-34364: Envoy OOM vector from HTTP async client with unbounded response buffer for mirror response, and other components
    • CVE-2024-32974: Crash in EnvoyQuicServerStream::OnInitialHeadersComplete()
    • CVE-2024-32975: Crash in QuicheDataReader::PeekVarInt62Length()
    • CVE-2024-32976: Endless loop while decompressing Brotli data with extra input
    • CVE-2024-23326: Envoy incorrectly accepts HTTP 200 response for entering upgrade mode
    • CVE-2024-38525: datadog tracer does not handle trace headers with unicode characters
  • The release also removes a transitive dependency on the gopkg.in/square/go-jose.v2 library which is vulnerable to GHSA-c5q2-7r4c-mv6g.

What's Changed
Changed

Full Changelog: pomerium/ingress-controller@v0.26.0...v0.26.1

v0.26.0

Compare Source

Upgrading
kubectl apply -k github.com/pomerium/ingress-controller/config/default\?ref=v0.26.0

See docs for further details.

What's Changed
Breaking
New
Fixes
Changed
Dependency Updates
New Contributors

Full Changelog: pomerium/ingress-controller@v0.25.2...v0.26.0


Configuration

📅 Schedule: Branch creation - "before 6am" in timezone America/Los_Angeles, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot force-pushed the renovate/pomerium-ingress-controller-0.26.x branch from cf25b0d to 937b1af Compare July 2, 2024 02:00
@renovate renovate bot changed the title chore(deps): update dependency pomerium/ingress-controller to v0.26.0 chore(deps): update dependency pomerium/ingress-controller to v0.26.1 Jul 2, 2024
@venkatamutyala venkatamutyala merged commit 6b14cdc into main Jul 16, 2024
3 checks passed
@venkatamutyala venkatamutyala deleted the renovate/pomerium-ingress-controller-0.26.x branch July 16, 2024 19:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant