Skip to content

Fix CVE-2024-44082 / OSSA-2024-003#1268

Merged
markgoddard merged 1 commit intostackhpc/2023.1from
ossa-2024-003-antelope
Sep 9, 2024
Merged

Fix CVE-2024-44082 / OSSA-2024-003#1268
markgoddard merged 1 commit intostackhpc/2023.1from
ossa-2024-003-antelope

Conversation

@priteau
Copy link
Copy Markdown
Member

@priteau priteau commented Sep 6, 2024

Fixes CVE-2024-44082 [1] with updated container images for Ironic services.

Note that Ironic Python Agent images also need to be updated to fully fix this vulnerability. If this is not possible, a new configuration option [conductor]conductor_always_validates_images is available. See the OSSA-2024-003 announcement [2] for more details.

[1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-44082
[2] https://security.openstack.org/ossa/OSSA-2024-003.html

Fixes CVE-2024-44082 [1] with updated container images for Ironic
services.

Note that Ironic Python Agent images also need to be updated to fully
fix this vulnerability. If this is not possible, a new configuration
option ``[conductor]conductor_always_validates_images`` is available.
See the OSSA-2024-003 announcement [2] for more details.

[1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-44082
[2] https://security.openstack.org/ossa/OSSA-2024-003.html
@priteau priteau self-assigned this Sep 6, 2024
@priteau priteau requested a review from a team as a code owner September 6, 2024 15:14
@markgoddard markgoddard merged commit 69012ee into stackhpc/2023.1 Sep 9, 2024
@markgoddard markgoddard deleted the ossa-2024-003-antelope branch September 9, 2024 09:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants