diff --git a/.changelog/581.txt b/.changelog/581.txt new file mode 100644 index 00000000..1089c4f5 --- /dev/null +++ b/.changelog/581.txt @@ -0,0 +1,3 @@ +```release-note:security +Upgrade envoy version to 1.28.5 to address [CVE-2024-39305](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39305) +``` \ No newline at end of file diff --git a/Dockerfile b/Dockerfile index 90d5b574..c34f2517 100644 --- a/Dockerfile +++ b/Dockerfile @@ -11,7 +11,7 @@ # prebuilt binaries in any other form. # ARG GOLANG_VERSION -FROM envoyproxy/envoy-distroless:v1.28.4 as envoy-binary +FROM envoyproxy/envoy-distroless:v1.28.5 as envoy-binary # Modify the envoy binary to be able to bind to privileged ports (< 1024). FROM debian:bullseye-slim AS setcap-envoy-binary @@ -27,7 +27,7 @@ RUN apt-get update && apt install -y libcap2-bin RUN setcap CAP_NET_BIND_SERVICE=+ep /usr/local/bin/envoy RUN setcap CAP_NET_BIND_SERVICE=+ep /usr/local/bin/$BIN_NAME -FROM hashicorp/envoy-fips:1.28.4-fips1402 as envoy-fips-binary +FROM hashicorp/envoy-fips:1.28.5-fips1402 as envoy-fips-binary # Modify the envoy-fips binary to be able to bind to privileged ports (< 1024). FROM debian:bullseye-slim AS setcap-envoy-fips-binary