Important: Network Observability 1.7.0 for OpenShift
A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in an OpenShift cluster to retrieve flows without authentication.
Moderate: Network Observability 1.6.2 for OpenShift
Moderate: Network Observability 1.6.1 for OpenShift
Important: Network Observability 1.6.0 for OpenShift
Moderate: Network Observability 1.5.0 for OpenShift
Important: Network Observability 1.4.0 for OpenShift
Network Observability 1.3.0 is an OpenShift operator that provides a monitoring pipeline to collect and enrich network flows that are produced by the Network observability eBPF agent.The operator provides dashboards, metrics, and keeps flows accessible in a queryable log store, Grafana Loki. When a FlowCollector is deployed, new dashboards are available in the Console.This update contains bug fixes.Security Fix(es): golang: html/template: improper handling of JavaScript whitespace (CVE-2023-24540) golang: html/template: improper sanitization of CSS values (CVE-2023-24539) golang: html/template: improper handling of empty HTML attributes (CVE-2023-29400) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.