github solo-io/gloo v1.4.2

3 years ago

CVEs

Updated envoy-gloo to one based on envoy master (1.15.0), which includes security fixes in envoy. For more details on the CVEs, see the envoy release notes here.

Note that one of the CVEs requires setting the global_downstream_max_connections, which may affect traffic if you perform a rolling upgrade from a version vulnerable to the CVE. The max connections is configurable and defaults to 250,000.

Dependency Bumps

  • envoy-gloo/solo-io has been upgraded to v1.15.0-rc1.

Fixes

  • Add Envoy host with port rule for Ingress (#3244)
  • Fix TCP multi-cluster routing by enabling routing via SNI name. Gloo adds new APIs to expose the envoy tcp SNI filter. (#3223)

Don't miss a new gloo release

NewReleases is sending notifications on new releases.