Package
tigera-operator-fips-1.38
Component
github.com/envoyproxy/gateway
Latest update
9.1
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
This vulnerability requires a version bump of github.com/envoyproxy/gateway to at least v1.7.4, which contains breaking API changes from the version currently in use in this tigera-operator version stream. Upgrading to the fixed version of github.com/envoyproxy/gateway must be coordinated by upstream maintainers. Users should transition to a fixed version stream of tigera-operator such as 1.42.
Status
Impact
The vulnerability requires a major version bump of github.com/envoyproxy/gateway to at least v1.7.4 and tigera-operator-1.38 is currently on v1.5.9. The requires significant changes to the tigera-operator code base by upstream maintainers. Users should transition to a fixed version stream of tigera-operator such as 1.42.
Status