Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update go-discover for recent AWS security patch. #6862

Closed
banks opened this issue Dec 2, 2019 · 1 comment · Fixed by #6865
Closed

Update go-discover for recent AWS security patch. #6862

banks opened this issue Dec 2, 2019 · 1 comment · Fixed by #6865
Assignees
Labels
pr/dependencies PR specifically updates dependencies of project type/enhancement Proposed improvement or new feature
Milestone

Comments

@banks
Copy link
Member

banks commented Dec 2, 2019

See hashicorp/go-discover#128

Once that's merged, we should pull it in and update vendor etc. As noted in that PR, I've already tested Consul's AWS integrations (auto join and CA) with that AWS SDK version.

Edit: note there is no vulnerability in the existing version here so no panic to upgrade but it's already tested so no reason not to and allow auto-join users additional protection from IMDS v2. For more details see: https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service/

@banks banks added security pr/dependencies PR specifically updates dependencies of project labels Dec 2, 2019
@banks banks added this to the 1.7.0 milestone Dec 2, 2019
@banks banks added type/enhancement Proposed improvement or new feature and removed security labels Dec 2, 2019
@ghost
Copy link

ghost commented Jan 25, 2020

Hey there,

This issue has been automatically locked because it is closed and there hasn't been any activity for at least 30 days.

If you are still experiencing problems, or still have questions, feel free to open a new one 👍.

@ghost ghost locked and limited conversation to collaborators Jan 25, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
pr/dependencies PR specifically updates dependencies of project type/enhancement Proposed improvement or new feature
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants