Skip to content

Fix CVE-2024-44082 / OSSA-2024-003 #1268

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Sep 9, 2024

Conversation

priteau
Copy link
Member

@priteau priteau commented Sep 6, 2024

Fixes CVE-2024-44082 [1] with updated container images for Ironic services.

Note that Ironic Python Agent images also need to be updated to fully fix this vulnerability. If this is not possible, a new configuration option [conductor]conductor_always_validates_images is available. See the OSSA-2024-003 announcement [2] for more details.

[1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-44082
[2] https://security.openstack.org/ossa/OSSA-2024-003.html

Fixes CVE-2024-44082 [1] with updated container images for Ironic
services.

Note that Ironic Python Agent images also need to be updated to fully
fix this vulnerability. If this is not possible, a new configuration
option ``[conductor]conductor_always_validates_images`` is available.
See the OSSA-2024-003 announcement [2] for more details.

[1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-44082
[2] https://security.openstack.org/ossa/OSSA-2024-003.html
@priteau priteau self-assigned this Sep 6, 2024
@priteau priteau requested a review from a team as a code owner September 6, 2024 15:14
@markgoddard markgoddard merged commit 69012ee into stackhpc/2023.1 Sep 9, 2024
12 checks passed
@markgoddard markgoddard deleted the ossa-2024-003-antelope branch September 9, 2024 09:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants