Skip to content

Conversation

priteau
Copy link
Member

@priteau priteau commented Sep 6, 2024

Fixes CVE-2024-44082 [1] with updated container images for Ironic services.

Note that Ironic Python Agent images also need to be updated to fully fix this vulnerability. If this is not possible, a new configuration option [conductor]conductor_always_validates_images is available. See the OSSA-2024-003 announcement [2] for more details.

[1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-44082
[2] https://security.openstack.org/ossa/OSSA-2024-003.html

Fixes CVE-2024-44082 [1] with updated container images for Ironic
services.

Note that Ironic Python Agent images also need to be updated to fully
fix this vulnerability. If this is not possible, a new configuration
option ``[conductor]conductor_always_validates_images`` is available.
See the OSSA-2024-003 announcement [2] for more details.

[1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-44082
[2] https://security.openstack.org/ossa/OSSA-2024-003.html
@priteau priteau self-assigned this Sep 6, 2024
@priteau priteau requested a review from a team as a code owner September 6, 2024 15:14
@markgoddard markgoddard merged commit 69012ee into stackhpc/2023.1 Sep 9, 2024
12 checks passed
@markgoddard markgoddard deleted the ossa-2024-003-antelope branch September 9, 2024 09:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants