Skip to content

Commit b2d8019

Browse files
Bump Kolla images for CVE-2024-36039
1 parent bc83165 commit b2d8019

File tree

2 files changed

+10
-6
lines changed

2 files changed

+10
-6
lines changed

etc/kayobe/kolla-image-tags.yml

Lines changed: 3 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -4,19 +4,16 @@
44
# where the key is the OS distro and the value is the tag to deploy.
55
kolla_image_tags:
66
openstack:
7+
rocky-9: 2023.1-rocky-9-20240621T104542
8+
ubuntu-jammy: 2023.1-ubuntu-jammy-20240621T104542
9+
bifrost_deploy:
710
rocky-9: 2023.1-rocky-9-20240423T125905
811
ubuntu-jammy: 2023.1-ubuntu-jammy-20240423T125905
9-
cloudkitty:
10-
rocky-9: 2023.1-rocky-9-20240509T111619
11-
ubuntu-jammy: 2023.1-ubuntu-jammy-20240509T111619
1212
haproxy_ssh:
1313
rocky-9: 2023.1-rocky-9-20240509T102329
1414
ubuntu-jammy: 2023.1-ubuntu-jammy-20240509T102329
1515
letsencrypt:
1616
rocky-9: 2023.1-rocky-9-20240509T102329
1717
ubuntu-jammy: 2023.1-ubuntu-jammy-20240509T102329
18-
magnum:
19-
rocky-9: 2023.1-rocky-9-20240607T082105
20-
ubuntu-jammy: 2023.1-ubuntu-jammy-20240607T082105
2118
opensearch:
2219
ubuntu-jammy: 2023.1-ubuntu-jammy-20240509T094444
Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
---
2+
security:
3+
- |
4+
Addresses critical vulnerability CVE-2024-36039 by
5+
bumping the PyMySQL library to 1.1.1 in all affected
6+
Kolla images. This vulnerability allows SQL injection
7+
through untrusted JSON objects.

0 commit comments

Comments
 (0)