Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

SUSE: 2020:1573-1 Moderate: Metrics Server, Cert Checker, vSphere VCP

suse
Calendar Grey June 9, 2020
Dist Suse Esm H88
SUSE Security Patch introduces enhancements for Performance Monitor, Certificate Validator, and additional tools, tackling moderate vulnerabilities.
An update that solves four vulnerabilities and has 16 fixes is now available

Summary

Metrics Server * Support monitoring of *CPU* and *memory* of a pod or node. Cert Status Checker * Exposes cluster-wide certificates status and use monitoring stack (Prometheus and Grafana) to receives alerts by Prometheus Alertmanager and monitors certificate status by Grafana dashboard. VSphere VCP * Allow Kubernetes pods to use VMWare vSphere Virtual Machine Disk (VMDK) volumes as persistent storage. Cilium Envoy * Updated Cilium from version 1.5.3 to version 1.6.6 * Provide Envoy-proxy support for Cilium * Envoy and its dependencies packaged for version 1.12.2 * Cilium uses CRD and ConfigMap points on etcd are removed See release notes for installation instructions: https://www.suse.com/releasenotes/x86_64/SUSE-CAASP/4/index.html Following CVE entries are relevant for the casp 4.2.1 update:

References

#1041090 #1047218 #1048688 #1086909 #1094448

#1095603 #1102920 #1121353 #1129568 #1138908

#1144068 #1151876 #1156450 #1159002 #1159003

#1159004 #1159539 #1162651 #1167073 #1169506

Cross- CVE-2019-18801 CVE-2019-18802 CVE-2019-18836

CVE-2019-18838

Affected Products:

SUSE CaaS Platform 4.0

https://www.suse.com/security/cve/CVE-2019-18801.html

https://www.suse.com/security/cve/CVE-2019-18802.html

https://www.suse.com/security/cve/CVE-2019-18836.html

https://www.suse.com/security/cve/CVE-2019-18838.html

https://bugzilla.suse.com/1041090

https://bugzilla.suse.com/1047218

https://bugzilla.suse.com/1048688

https://bugzilla.suse.com/1086909

https://bugzilla.suse.com/1094448

https://bugzilla.suse.com/1095603

Announcement ID: SUSE-SU-2020:1573-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here