Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Latest Released Image Contains Shellshock Vulnerability #5

Open
isugimpy opened this issue Sep 18, 2020 · 2 comments
Open

Latest Released Image Contains Shellshock Vulnerability #5

isugimpy opened this issue Sep 18, 2020 · 2 comments

Comments

@isugimpy
Copy link

As per title, https://hub.docker.com/layers/istio/coredns-plugin/0.2-istio-1.1/images/sha256-964eca01e487bcedcc769dd22644a4272daebf079b64170dd6bab16662651b99?context=explore contains the Shellshock vulnerability and hasn't been built in 2 years. Would it be possible for an updated version of the image to be built and released officially with the exploit patched?

@rshriram
Copy link
Collaborator

Hi. Sorry for the delay. This plugin is no longer maintained nor necessary as of Istio 1.8, as the DNS functionality is built into Istio sidecars. The functionality in 1.8 is far more richer and automatically configured than the current coredns plugin. I encourage you to take that for a spin.

Sidecar DNs is enabled by default in the preview profile. You can also enable it manually by setting the following config in the istio operator (Istio 1.8 onwards)

  meshConfig:
    defaultConfig:
      proxyMetadata:
        ISTIO_META_DNS_CAPTURE: "true"
        ISTIO_META_PROXY_XDS_VIA_AGENT: "true"

@isugimpy
Copy link
Author

I appreciate the response on this, but 1.8 isn't a viable option for us yet, because we're still working on getting upgraded from k8s 1.14. Thank you for the information, though! I'll keep that in mind for when we're able to upgrade.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants