Oval Definition:oval:org.opensuse.security:def:73027
Revision Date:2020-12-01Version:1
Title:Add features for Metrics Server, Cert Status Checker, VSphere VCP, and Cilium Envoy (Moderate)
Description:





Metrics Server

* Support monitoring of *CPU* and *memory* of a pod or node. Cert Status Checker * Exposes cluster-wide certificates status and use monitoring stack (Prometheus and Grafana) to receives alerts by Prometheus Alertmanager and monitors certificate status by Grafana dashboard. VSphere VCP * Allow Kubernetes pods to use VMWare vSphere Virtual Machine Disk (VMDK) volumes as persistent storage. Cilium Envoy * Updated Cilium from version 1.5.3 to version 1.6.6 * Provide Envoy-proxy support for Cilium * Envoy and its dependencies packaged for version 1.12.2 * Cilium uses CRD and ConfigMap points on etcd are removed See release notes for installation instructions: https://www.suse.com/releasenotes/x86_64/SUSE-CAASP/4/



Following CVE entries are relevant for the casp 4.2.1 update:



cilium-proxy:

CVE-2019-18801: An untrusted remote client might have been able to send HTTP/2 requests via cilium-proxyx that could have written to the heap outside of the request buffers when the upstream is HTTP/1. (bsc#1159002) CVE-2019-18802: A malformed request header may have caused bypass of route matchers resulting in escalation of privileges or information disclosure (bsc#1159003) CVE-2019-18838: A malformed HTTP request without the Host header may cause abnormal termination ofthe Envoy process (bsc#1159004) CVE-2019-18836: Excessive iteration due to listener filter timeout in envoy could lead to DoS (bsc#1156450)

kafka:

CVE-2018-1288: authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request. (bsc#1102920)
Family:unixClass:patch
Status:Reference(s):1041090
1047218
1048688
1086909
1094448
1095603
1102920
1121353
1129568
1138908
1144068
1151876
1156450
1159002
1159003
1159004
1159539
1162651
1167073
1169506
CVE-2014-9114
CVE-2015-5218
CVE-2016-2779
CVE-2016-5011
CVE-2017-2616
CVE-2018-7738
CVE-2019-18801
CVE-2019-18802
CVE-2019-18836
CVE-2019-18838
Platform(s):SUSE CaaS Platform 4.0
SUSE Linux Enterprise Module for Basesystem 15 SP2
Product(s):
Definition Synopsis
  • SUSE CaaS Platform 4.0 is installed
  • AND Package Information
  • caasp-release-4.2.1-24.23 is installed
  • OR skuba-1.3.5-3.39 is installed
  • OR skuba-update-1.3.5-3.39 is installed
  • OR terraform-provider-vsphere-1.17.3-3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP2 is installed
  • AND Package Information
  • libblkid-devel-2.33.1-4.5 is installed
  • OR libblkid-devel-static-2.33.1-4.5 is installed
  • OR libblkid1-2.33.1-4.5 is installed
  • OR libblkid1-32bit-2.33.1-4.5 is installed
  • OR libfdisk-devel-2.33.1-4.5 is installed
  • OR libfdisk1-2.33.1-4.5 is installed
  • OR libmount-devel-2.33.1-4.5 is installed
  • OR libmount1-2.33.1-4.5 is installed
  • OR libmount1-32bit-2.33.1-4.5 is installed
  • OR libsmartcols-devel-2.33.1-4.5 is installed
  • OR libsmartcols1-2.33.1-4.5 is installed
  • OR libuuid-devel-2.33.1-4.5 is installed
  • OR libuuid-devel-static-2.33.1-4.5 is installed
  • OR libuuid1-2.33.1-4.5 is installed
  • OR libuuid1-32bit-2.33.1-4.5 is installed
  • OR util-linux-2.33.1-4.5 is installed
  • OR util-linux-lang-2.33.1-4.5 is installed
  • OR util-linux-systemd-2.33.1-4.5 is installed
  • BACK