Maintained with ☕️ by
IcePanel logo

1.21.5-asm.21 is now available for in-cluster Cloud Service Mesh

Share

Services

## Security **1.21.5-asm.21 is now available for in-cluster Cloud Service Mesh.** This patch release contains a fix for a bug where [mixed case hosts in Gateway and TLS redirect results in stale RDS](https://github.com/istio/istio/issues/49638). This patch release also contains the fix for a security vulnerability where [an attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing](https://github.com/advisories/GHSA-w32m-9786-jp63). For details on upgrading Cloud Service Mesh, refer to [Upgrade Cloud Service Mesh](https://cloud.google.com/service-mesh/v1.21/docs/upgrade/upgrade). Cloud Service Mesh v1.21.5-asm.21 uses Envoy v1.29.12. ## Security **1.22.7-asm.4 is now available for in-cluster Cloud Service Mesh.** This patch release contains the fix for a security vulnerability where [an attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing](https://github.com/advisories/GHSA-w32m-9786-jp63). For details on upgrading Cloud Service Mesh, see [Upgrade Cloud Service Mesh](https://cloud.google.com/service-mesh/docs/upgrade/upgrade).Cloud Service Mesh version 1.22.7-asm.4 uses envoy v1.30.9. ## Security **1.23.4-asm.7 is now available for in-cluster Cloud Service Mesh.** This patch release contains fixes for a bug in envoy config where `opencensus.proto.trace.v1.TraceConfig` has been disabled by default and an issue causing VirtualService header name validation to reject valid header names. This patch release also contains the fix for a security vulnerability where [an attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing](https://github.com/advisories/GHSA-w32m-9786-jp63). For details on upgrading Cloud Service Mesh, refer to [Upgrade Cloud Service Mesh](https://cloud.google.com/service-mesh/docs/upgrade/upgrade). Cloud Service Mesh v1.23.4-asm.7 uses Envoy v1.31.5.