-
Wed Jul 15 2020 Tom Cocozzello <tom.cocozzello@oracle.com> - 1.14.9-1.0.6
- CVE-2020-8559: Privilege escalation from compromised node to cluster
- CVE-2020-8557: Node disk DOS by writing to container /etc/hosts
-
Mon Jun 29 2020 Daniel Krasinski <daniel.krasinski@oracle.com> - 1.14.9-1.0.5
- Update dependency on Kata containers to a build that includes fixes for CVE-2020-2023 thru CVE-2020-2026
-
Thu Jun 04 2020 Thomas Tanaka <thomas.tanaka@oracle.com> - 1.14.9-1.0.4
- CVE-2020-10749: IPv4 only clusters susceptible to MitM attacks via IPv6 rogue router advertisements
- CVE-2020-8555: Half-Blind SSRF in kube-controller-manager
-
Fri Apr 03 2020 Thomas Tanaka <thomas.tanaka@oracle.com> - 1.14.9-1.0.3
- [CVE-2019-11254] kube-apiserver Denial of Service vulnerability from malicious YAML payloads
-
Wed Feb 12 2020 Tom Cocozzello <tom.cocozzello@oracle.com> - 1.14.9-1.0.2
- Use bounded crio version
-
Thu Nov 14 2019 Tom Cocozzello <tom.cocozzello@oracle.com> - 1.14.9-1.0.1
- Added Oracle specific build files for Kubernetes