From 5bf1d45ebc55a7f9ed6f06d791afd44796c0cf99 Mon Sep 17 00:00:00 2001 From: hc-github-team-consul-core Date: Fri, 5 Jul 2024 08:59:39 -0700 Subject: [PATCH] Backport of Bump envoy 1.28.5 into release/1.4.x (#581) bump envoy Co-authored-by: Sarah Alsmiller --- .changelog/581.txt | 3 +++ Dockerfile | 4 ++-- 2 files changed, 5 insertions(+), 2 deletions(-) create mode 100644 .changelog/581.txt diff --git a/.changelog/581.txt b/.changelog/581.txt new file mode 100644 index 00000000..1089c4f5 --- /dev/null +++ b/.changelog/581.txt @@ -0,0 +1,3 @@ +```release-note:security +Upgrade envoy version to 1.28.5 to address [CVE-2024-39305](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39305) +``` \ No newline at end of file diff --git a/Dockerfile b/Dockerfile index 90d5b574..c34f2517 100644 --- a/Dockerfile +++ b/Dockerfile @@ -11,7 +11,7 @@ # prebuilt binaries in any other form. # ARG GOLANG_VERSION -FROM envoyproxy/envoy-distroless:v1.28.4 as envoy-binary +FROM envoyproxy/envoy-distroless:v1.28.5 as envoy-binary # Modify the envoy binary to be able to bind to privileged ports (< 1024). FROM debian:bullseye-slim AS setcap-envoy-binary @@ -27,7 +27,7 @@ RUN apt-get update && apt install -y libcap2-bin RUN setcap CAP_NET_BIND_SERVICE=+ep /usr/local/bin/envoy RUN setcap CAP_NET_BIND_SERVICE=+ep /usr/local/bin/$BIN_NAME -FROM hashicorp/envoy-fips:1.28.4-fips1402 as envoy-fips-binary +FROM hashicorp/envoy-fips:1.28.5-fips1402 as envoy-fips-binary # Modify the envoy-fips binary to be able to bind to privileged ports (< 1024). FROM debian:bullseye-slim AS setcap-envoy-fips-binary