|
| 1 | +--- |
| 2 | +upgrade: |
| 3 | + - | |
| 4 | + Bumped pulp repo versions for Q2 2024 |
| 5 | + Bumped Kolla image tags for Q2 2024 |
| 6 | + Bumped prometheus server to 2.51.1 |
| 7 | + Bumped prometheus alertmanager to 0.26.0 |
| 8 | + Bumped prometheus blackbox exporter to 0.25.0 |
| 9 | + Bumped prometheus cadvisor exporter to 0.49.1 |
| 10 | + Bumped haproxy exporter to 0.15.0 |
| 11 | + Bumped prometheus memcached exporter to 0.14.3 |
| 12 | + Bumped prometheus msteams to 1.5.2 |
| 13 | + Bumped prometheus mtail to 3.0.0-rc53 |
| 14 | + Bumped mysqld exporter to 0.15.1 |
| 15 | + Bumped node exporter to 1.7.0 |
| 16 | + Bumped prometheus openstack exporter to 1.7.0 |
| 17 | + Bumped prometheus ovn exporter to 1.0.7 |
| 18 | + Bumped opensearch to 2.13.0 |
| 19 | + Bumped grafana to 10.4.2 |
| 20 | +security: |
| 21 | + - | |
| 22 | + Fixed CVE-2023-31047, CVE-2023-23969, CVE-2023-24580, CVE-2023-36053, |
| 23 | + CVE-2023-46695, CVE-2023-30861, CVE-2022-4899. CVE-2024-1135, |
| 24 | + GHSA-2m57-hf25-phgg, CVE-2023-0286, CVE-2023-50782, CVE-2024-26130 |
| 25 | + for openstack services. |
| 26 | + Fixed CVE-2022-41723, CVE-2023-39325 (except prometheus-alertmanager, |
| 27 | + prometheus-msteams-exporter, prometheus-haproxy-exporter, |
| 28 | + prometheus-openstack-exporter. No patch available.), CVE-2021-43565, |
| 29 | + CVE-2022-27191, CVE-2022-27664, CVE-2021-38561, CVE-2022-21698, |
| 30 | + CVE-2021-4238, CVE-2022-40083, CVE-2022-41721, CVE-2021-33194, |
| 31 | + CVE-2023-2253, CVE-2023-27561, CVE-2023-28840, CVE-2024-21626, |
| 32 | + CVE-2022-32149, CVE-2023-45142, GHSA-m425-mq94-257g |
| 33 | + for prometheus server and exporters except prometheus-libvirt-exporter |
| 34 | + and prometheus-haproxy-exporter. (Source repository of each are archived |
| 35 | + and no longer maintained) |
| 36 | +
|
| 37 | + Fixed CVE-2023-39325, CVE-2023-45142, CVE-2023-47108, CVE-2023-49568, |
| 38 | + CVE-2023-49569, GHSA-9763-4f94-gfch, GHSA-m425-mq94-257g |
| 39 | + for grafana. |
| 40 | + It is advised to redeploy service with current version of images from |
| 41 | + StackHPC Release Train. |
0 commit comments