forked from openstack/kolla
-
Notifications
You must be signed in to change notification settings - Fork 3
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Closes-Bug: #1985784 Change-Id: I66476a2b396e2cbe41e68ac51f57aae1806b2ed8 (cherry picked from commit 5b1da01)
- Loading branch information
1 parent
b64e717
commit 5056b65
Showing
5 changed files
with
24 additions
and
53 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,16 @@ | ||
--- | ||
security: | ||
- | | ||
Fixes CVE-2022-38060, a sudo privilege escalation vulnerability. | ||
`LP#1985784 <https://launchpad.net/bugs/1889611>`__ | ||
upgrade: | ||
- | | ||
To fix CVE-2022-38060, support for KOLLA_CONFIG and KOLLA_CONFIG_FILE | ||
environment variables in kolla-built containers has been dropped. | ||
Now, only the single trusted path of | ||
``/var/lib/kolla/config_files/config.json`` will be utilised for loading | ||
container config. | ||
We believe this is a reasonable tradeoff as these environment variables | ||
were not used by any known downstream and potential users in the wild | ||
can easily adapt as this does not limit the functionality per se, only | ||
making it stricter as to where the config can come from. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters