1.15.13 Enterprise (July 11, 2024)
Enterprise LTS: Consul Enterprise 1.15 is a Long-Term Support (LTS) release.
SECURITY:
- Upgrade envoy module dependencies to version 1.27.7, 1.28.5 and 1.29.7 or higher to resolve CVE-2024-39305 [GH-21524]
- Upgrade go version to 1.22.5 to address CVE-2024-24791 [GH-21507]
- Upgrade go-retryablehttp to address CVE-2024-6104 [GH-21384]
- agent: removed reflected cross-site scripting vulnerability [GH-21342]
- ui: Pin and namespace sub-module dependencies related to the Consul UI [GH-21378]
IMPROVEMENTS:
- mesh: update supported envoy version 1.29.4
- upgrade go version to v1.22.3. [GH-21113]
- upgrade go version to v1.22.4. [GH-21265]
BUG FIXES:
- core: Fix panic runtime error on AliasCheck [GH-21339]
- terminating-gateway: (Enterprise Only) Fixed issue where enterprise metadata applied to linked services was the terminating-gateways enterprise metadata and not the linked services enterprise metadata. [GH-21382]
- txn: Fix a bug where mismatched Consul server versions could result in undetected data loss for when using newer Transaction verbs. [GH-21519]