openshift / origin-aggregated-logging

139 stars 231 forks source link

Bug 2031028: Bump ES binary to 6.8.1.redhat-00012 to mitigate CVE-2021-44228 #2217

Closed periklis closed 2 years ago

periklis commented 2 years ago

Description

This PR provides a fix that references an Elasticsearch binary build with Project Newcastle that includes the following upstream PR: https://github.com/elastic/elasticsearch/pull/81632

It addresses OpenShift Logging releases 4.6.z /cc @igor-karpukhin @jcantrill

Links

openshift-ci[bot] commented 2 years ago

@periklis: This pull request references Bugzilla bug 2031028, which is valid. The bug has been moved to the POST state. The bug has been updated to refer to the pull request using the external bug tracker.

2 validation(s) were run on this bug * bug target release (4.6.z) matches configured target release for branch (4.6.z) * bug is in the state ASSIGNED, which is one of the valid states (NEW, ASSIGNED, ON_DEV, POST, POST)

No GitHub users were found matching the public email listed for the QA contact in Bugzilla (anli@redhat.com), skipping review request.

In response to [this](https://github.com/openshift/origin-aggregated-logging/pull/2217): >Bug 2031028: Bump ES binary to 6.8.1.redhat-00012 to mitigate CVE-2021-44228 Instructions for interacting with me using PR comments are available [here](https://git.k8s.io/community/contributors/guide/pull-requests.md). If you have questions or suggestions related to my behavior, please file an issue against the [kubernetes/test-infra](https://github.com/kubernetes/test-infra/issues/new?title=Prow%20issue:) repository.
joepvd commented 2 years ago

/retest

jcantrill commented 2 years ago

/approve /lgtm

jcantrill commented 2 years ago

/retest

openshift-ci[bot] commented 2 years ago

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: jcantrill, periklis

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files: - ~~[OWNERS](https://github.com/openshift/origin-aggregated-logging/blob/release-4.6/OWNERS)~~ [jcantrill] Approvers can indicate their approval by writing `/approve` in a comment Approvers can cancel approval by writing `/approve cancel` in a comment
openshift-ci[bot] commented 2 years ago

@periklis: all tests passed!

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available [here](https://git.k8s.io/community/contributors/guide/pull-requests.md). If you have questions or suggestions related to my behavior, please file an issue against the [kubernetes/test-infra](https://github.com/kubernetes/test-infra/issues/new?title=Prow%20issue:) repository. I understand the commands that are listed [here](https://go.k8s.io/bot-commands).
periklis commented 2 years ago

/label backport-risk-assessed

openshift-ci[bot] commented 2 years ago

@periklis: All pull requests linked via external trackers have merged:

Bugzilla bug 2031028 has been moved to the MODIFIED state.

In response to [this](https://github.com/openshift/origin-aggregated-logging/pull/2217): >Bug 2031028: Bump ES binary to 6.8.1.redhat-00012 to mitigate CVE-2021-44228 Instructions for interacting with me using PR comments are available [here](https://git.k8s.io/community/contributors/guide/pull-requests.md). If you have questions or suggestions related to my behavior, please file an issue against the [kubernetes/test-infra](https://github.com/kubernetes/test-infra/issues/new?title=Prow%20issue:) repository.