Skip to content

Commit 4282971

Browse files
authored
Merge pull request #1115 from stackhpc/security/CVE-2024-36039
Bump Kolla images for CVE-2024-36039
2 parents 1e00166 + 122a5f1 commit 4282971

File tree

3 files changed

+11
-7
lines changed

3 files changed

+11
-7
lines changed

.github/workflows/stackhpc-all-in-one.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -167,7 +167,7 @@ jobs:
167167
VM_NETWORK: ${{ inputs.vm_network }}
168168
VM_SUBNET: ${{ inputs.vm_subnet }}
169169
VM_INTERFACE: ${{ inputs.vm_interface }}
170-
VM_VOLUME_SIZE: ${{ inputs.upgrade && '50' || '35' }}
170+
VM_VOLUME_SIZE: ${{ inputs.upgrade && '50' || '40' }}
171171
VM_TAGS: '["skc-ci-aio", "PR=${{ github.event.number }}"]'
172172

173173
- name: Terraform Plan

etc/kayobe/kolla-image-tags.yml

Lines changed: 3 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -4,14 +4,14 @@
44
# where the key is the OS distro and the value is the tag to deploy.
55
kolla_image_tags:
66
openstack:
7+
rocky-9: 2023.1-rocky-9-20240621T104542
8+
ubuntu-jammy: 2023.1-ubuntu-jammy-20240621T104542
9+
bifrost_deploy:
710
rocky-9: 2023.1-rocky-9-20240423T125905
811
ubuntu-jammy: 2023.1-ubuntu-jammy-20240423T125905
912
cinder:
1013
rocky-9: 2023.1-rocky-9-20240701T123544
1114
ubuntu-jammy: 2023.1-ubuntu-jammy-20240701T123544
12-
cloudkitty:
13-
rocky-9: 2023.1-rocky-9-20240509T111619
14-
ubuntu-jammy: 2023.1-ubuntu-jammy-20240509T111619
1515
glance:
1616
rocky-9: 2023.1-rocky-9-20240701T123544
1717
ubuntu-jammy: 2023.1-ubuntu-jammy-20240701T123544
@@ -21,9 +21,6 @@ kolla_image_tags:
2121
letsencrypt:
2222
rocky-9: 2023.1-rocky-9-20240509T102329
2323
ubuntu-jammy: 2023.1-ubuntu-jammy-20240509T102329
24-
magnum:
25-
rocky-9: 2023.1-rocky-9-20240607T082105
26-
ubuntu-jammy: 2023.1-ubuntu-jammy-20240607T082105
2724
nova:
2825
rocky-9: 2023.1-rocky-9-20240702T082319
2926
ubuntu-jammy: 2023.1-ubuntu-jammy-20240702T082319
Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
---
2+
security:
3+
- |
4+
Addresses critical vulnerability CVE-2024-36039 by
5+
bumping the PyMySQL library to 1.1.1 in all affected
6+
Kolla images. This vulnerability allows SQL injection
7+
through untrusted JSON objects.

0 commit comments

Comments
 (0)