-
Notifications
You must be signed in to change notification settings - Fork 355
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(deps): update module github.com/cilium/cilium to v1.16.6 [security] #1844
Open
renovate
wants to merge
1
commit into
main
Choose a base branch
from
renovate/go-github.com-cilium-cilium-vulnerability
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
renovate
bot
force-pushed
the
renovate/go-github.com-cilium-cilium-vulnerability
branch
3 times, most recently
from
August 21, 2024 10:07
5243393
to
b9de45f
Compare
renovate
bot
force-pushed
the
renovate/go-github.com-cilium-cilium-vulnerability
branch
2 times, most recently
from
August 29, 2024 10:06
64008ff
to
d223c73
Compare
renovate
bot
force-pushed
the
renovate/go-github.com-cilium-cilium-vulnerability
branch
5 times, most recently
from
September 8, 2024 02:54
cbb34ad
to
8153671
Compare
renovate
bot
force-pushed
the
renovate/go-github.com-cilium-cilium-vulnerability
branch
2 times, most recently
from
September 9, 2024 14:58
e4a63d8
to
f969d43
Compare
renovate
bot
force-pushed
the
renovate/go-github.com-cilium-cilium-vulnerability
branch
2 times, most recently
from
September 20, 2024 07:55
23b1c7c
to
d25612b
Compare
renovate
bot
force-pushed
the
renovate/go-github.com-cilium-cilium-vulnerability
branch
2 times, most recently
from
October 16, 2024 04:57
27f2299
to
8f6e223
Compare
renovate
bot
force-pushed
the
renovate/go-github.com-cilium-cilium-vulnerability
branch
3 times, most recently
from
October 21, 2024 20:31
a6fe1b5
to
c6186ec
Compare
renovate
bot
changed the title
fix(deps): update module github.com/cilium/cilium to v1.14.14 [security]
fix(deps): update module github.com/cilium/cilium to v1.14.16 [security]
Oct 21, 2024
renovate
bot
force-pushed
the
renovate/go-github.com-cilium-cilium-vulnerability
branch
4 times, most recently
from
October 30, 2024 10:28
2ccaf97
to
d540971
Compare
renovate
bot
force-pushed
the
renovate/go-github.com-cilium-cilium-vulnerability
branch
2 times, most recently
from
November 7, 2024 06:06
1886b51
to
8b60283
Compare
renovate
bot
force-pushed
the
renovate/go-github.com-cilium-cilium-vulnerability
branch
4 times, most recently
from
December 2, 2024 07:09
8b3c465
to
d7ea150
Compare
renovate
bot
force-pushed
the
renovate/go-github.com-cilium-cilium-vulnerability
branch
5 times, most recently
from
January 9, 2025 10:59
a3bb9d8
to
dfbc269
Compare
renovate
bot
force-pushed
the
renovate/go-github.com-cilium-cilium-vulnerability
branch
2 times, most recently
from
January 10, 2025 11:41
b3a8eaa
to
e964dbc
Compare
renovate
bot
changed the title
fix(deps): update module github.com/cilium/cilium to v1.14.16 [security]
Update module github.com/cilium/cilium to v1.14.16 [SECURITY]
Jan 10, 2025
renovate
bot
force-pushed
the
renovate/go-github.com-cilium-cilium-vulnerability
branch
7 times, most recently
from
January 17, 2025 15:31
7358858
to
33b412b
Compare
renovate
bot
changed the title
Update module github.com/cilium/cilium to v1.14.16 [SECURITY]
fix(deps): update module github.com/cilium/cilium to v1.14.16 [security]
Jan 17, 2025
renovate
bot
force-pushed
the
renovate/go-github.com-cilium-cilium-vulnerability
branch
2 times, most recently
from
January 20, 2025 07:01
82bab8a
to
8d43611
Compare
renovate
bot
changed the title
fix(deps): update module github.com/cilium/cilium to v1.14.16 [security]
fix(deps): update module github.com/cilium/cilium to v1.14.16 [security] - autoclosed
Jan 20, 2025
renovate
bot
deleted the
renovate/go-github.com-cilium-cilium-vulnerability
branch
January 20, 2025 15:52
renovate
bot
changed the title
fix(deps): update module github.com/cilium/cilium to v1.14.16 [security] - autoclosed
fix(deps): update module github.com/cilium/cilium to v1.14.16 [security]
Jan 23, 2025
renovate
bot
force-pushed
the
renovate/go-github.com-cilium-cilium-vulnerability
branch
from
January 23, 2025 20:34
9f7100c
to
8d43611
Compare
renovate
bot
changed the title
fix(deps): update module github.com/cilium/cilium to v1.14.16 [security]
fix(deps): update module github.com/cilium/cilium to v1.16.6 [security]
Jan 23, 2025
|
renovate
bot
force-pushed
the
renovate/go-github.com-cilium-cilium-vulnerability
branch
2 times, most recently
from
January 24, 2025 05:41
cf38b3d
to
fb18e12
Compare
renovate
bot
force-pushed
the
renovate/go-github.com-cilium-cilium-vulnerability
branch
from
January 25, 2025 07:49
fb18e12
to
4e457d7
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
None yet
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v1.16.5
->v1.16.6
GitHub Vulnerability Alerts
CVE-2025-23047
Impact
For users who deploy Hubble UI using either Cilium CLI or via the Cilium Helm chart, an insecure default
Access-Control-Allow-Origin
header value could lead to sensitive data exposure. A user with access to a Hubble UI instance affected by this issue could leak configuration details about the Kubernetes cluster which Hubble UI is monitoring, including node names, IP addresses, and other metadata about workloads and the cluster networking configuration. In order for this vulnerability to be exploited, a victim would have to first visit a malicious page.Patches
This issue was patched in cilium/cilium@a3489f1
This issue affects:
This issue is patched in:
Workarounds
Users who deploy Hubble UI using the Cilium Helm chart directly can remove the CORS headers from the Helm template as shown in the patch.
Acknowledgements
The Cilium community has worked together with members of Isovalent to prepare these mitigations. Special thanks to @ciffelia for reporting this issue and to @geakstr for the fix.
For more information
If you have any questions or comments about this advisory, please reach out on Slack.
If you think you have found a vulnerability affecting Cilium, we strongly encourage you to report it to our security mailing list at [email protected]. This is a private mailing list for the Cilium security team, and your report will be treated as top priority.
Release Notes
cilium/cilium (github.com/cilium/cilium)
v1.16.6
: 1.16.6Compare Source
Summary of Changes
Major Changes:
Minor Changes:
Bugfixes:
CI Changes:
Misc Changes:
7c3c3ce
(v1.16) (#36609, @cilium-renovate[bot])1a6e657
(v1.16) (#36850, @cilium-renovate[bot])9855006
(v1.16) (#36610, @cilium-renovate[bot])make -C Documentation update-cmdref
when make uses--jobserver-style=fifo
. (Backport PR #36872, Upstream PR #36788, @gentoo-root)Other Changes:
Docker Manifests
cilium
quay.io/cilium/cilium:v1.16.6@​sha256:1e0896b1c4c188b4812c7e0bed7ec3f5631388ca88325c1391a0ef9172c448da
quay.io/cilium/cilium:stable@sha256:1e0896b1c4c188b4812c7e0bed7ec3f5631388ca88325c1391a0ef9172c448da
clustermesh-apiserver
quay.io/cilium/clustermesh-apiserver:v1.16.6@​sha256:ab2070ea48a52a55d961b81b7b5fbac7d40a3f428be9b1b6b9071d47f194456a
quay.io/cilium/clustermesh-apiserver:stable@sha256:ab2070ea48a52a55d961b81b7b5fbac7d40a3f428be9b1b6b9071d47f194456a
docker-plugin
quay.io/cilium/docker-plugin:v1.16.6@​sha256:f8f5833a60900b0264fd8982b11329e130c1a326afe2e4653e9f2d2e3fb2af66
quay.io/cilium/docker-plugin:stable@sha256:f8f5833a60900b0264fd8982b11329e130c1a326afe2e4653e9f2d2e3fb2af66
hubble-relay
quay.io/cilium/hubble-relay:v1.16.6@​sha256:ca8dcaa5a81a37743b1397ba2221d16d5d63e4a47607584f1bf50a3b0882bf3b
quay.io/cilium/hubble-relay:stable@sha256:ca8dcaa5a81a37743b1397ba2221d16d5d63e4a47607584f1bf50a3b0882bf3b
operator-alibabacloud
quay.io/cilium/operator-alibabacloud:v1.16.6@​sha256:0e3c7fbcb6bde9a247cd2dd3d25230e2859d40d2eb58aba6265a2aab216775a9
quay.io/cilium/operator-alibabacloud:stable@sha256:0e3c7fbcb6bde9a247cd2dd3d25230e2859d40d2eb58aba6265a2aab216775a9
operator-aws
quay.io/cilium/operator-aws:v1.16.6@​sha256:d11ee1cfa3465defe2df7ec1c6e8a77bcaf280b44d2c61aa7496c58b29550f6d
quay.io/cilium/operator-aws:stable@sha256:d11ee1cfa3465defe2df7ec1c6e8a77bcaf280b44d2c61aa7496c58b29550f6d
operator-azure
quay.io/cilium/operator-azure:v1.16.6@​sha256:0a05d7aea760923897aabd715213ab11a706051673d41fab3874a37f897c1bdd
quay.io/cilium/operator-azure:stable@sha256:0a05d7aea760923897aabd715213ab11a706051673d41fab3874a37f897c1bdd
operator-generic
quay.io/cilium/operator-generic:v1.16.6@​sha256:13d32071d5a52c069fb7c35959a56009c6914439adc73e99e098917646d154fc
quay.io/cilium/operator-generic:stable@sha256:13d32071d5a52c069fb7c35959a56009c6914439adc73e99e098917646d154fc
operator
quay.io/cilium/operator:v1.16.6@​sha256:09ab2878e103fa32a00fd1fe4469f7042cfb053627b44c82fa03a04a820c0b46
quay.io/cilium/operator:stable@sha256:09ab2878e103fa32a00fd1fe4469f7042cfb053627b44c82fa03a04a820c0b46
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.