Skip to content

Backport of [NET-6138] security: Bump google.golang.org/grpc to 1.56.3 (CVE-2023-44487) to release/1.17.x#19417

Merged
zalimeni merged 1 commit into
release/1.17.xfrom
backport/net-6138/release-1.17.x
Oct 30, 2023
Merged

Backport of [NET-6138] security: Bump google.golang.org/grpc to 1.56.3 (CVE-2023-44487) to release/1.17.x#19417
zalimeni merged 1 commit into
release/1.17.xfrom
backport/net-6138/release-1.17.x

Conversation

@zalimeni
Copy link
Copy Markdown
Member

Backport

This PR is manually generated from #19414 to be assessed for backporting.

The below text is copied from the body of the original PR.


Description

Upgrade google.golang.org/grpc to 1.56.3 (where 1.57.x is already in use, upgrade to 1.57.2) to mitigate CVE-2023-44487.

1.56.3 was chosen as the earliest minor release line to receive a patch for this vulnerability in order to minimize change prior to the 1.17 release of Consul; a later upgrade should consider moving to the latest minor version of gRPC. A review of the release notes and changelog between 1.55.0 and 1.56.3 was conducted to check for unreported breaking changes.

Testing & Reproduction steps

CI tests should continue to pass.

Links

PR Checklist

  • updated test coverage
  • external facing docs updated
  • appropriate backport labels added
  • not a security concern

@github-actions github-actions Bot added the pr/dependencies PR specifically updates dependencies of project label Oct 27, 2023
@zalimeni zalimeni merged commit 4c3c32d into release/1.17.x Oct 30, 2023
@zalimeni zalimeni deleted the backport/net-6138/release-1.17.x branch October 30, 2023 12:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pr/dependencies PR specifically updates dependencies of project pr/no-backport theme/security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants