You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@@ -41,6 +41,8 @@ Nginx controller has been deprecated by the upstream provider, and we are in the
41
41
controller. Until the migration to Traefik ingress is complete, we will be upgrading Nginx controller to version 1.13.7,
42
42
which will remediate this vulnerability.
43
43
44
+
We will update this security advisory when Palette versions with the updated Nginx controller have been released.
45
+
44
46
### Affected Deployments
45
47
46
48
<!-- prettier-ignore-start -->
@@ -59,25 +61,303 @@ which will remediate this vulnerability.
59
61
60
62
<!-- prettier-ignore-start -->
61
63
62
-
We recommend taking the following actions to remediate CVE-2026-24514:
64
+
We recommend taking the following actions to remediate CVE-2026-2451.
63
65
64
-
-**Multi-tenant and dedicated SaaS deployments** - No action necessary. Deployments will be patched as part of the standard update process.
65
-
-**Self-hosted deployments** - Update the <VersionedLinktext="Nginx"url="/integrations/packs/?pack=nginx" /> pack version to 1.13.7.
66
-
-**Workload clusters**
66
+
#### Multi-tenant and Dedicated SaaS Deployments
67
67
68
-
- Managed Kubernetes clusters (AKS, EKS, GKE) should be updated with patches from the cloud vendor as soon as they become available.
69
-
- Patched OS images for other cluster types will be available in an upcoming release. All customers are advised to upgrade to the latest Kubernetes patch versions as soon as they become available.
70
-
- A patch for Edge clusters will be available in an upcoming release. All customers are advised to upgrade the clusters to the patched version as soon as they become available.
68
+
No action necessary. Deployments will be patched as part of the standard update process.
71
69
72
-
<!-- prettier-ignore-end -->
70
+
#### Palette Enterprise or VerteX Installed with Helm Charts
73
71
74
-
If possible, we also recommend taking the following actions:
72
+
If you have any instances of Palette enterprise or VerteX installed via Helm Charts with the affected version of the
73
+
`ingress-nginx-controller` DaemonSet, you must update it to version `1.13.7`. Follow the steps below to download the
74
+
updated version of the component and update your instance.
75
75
76
-
- Avoid running untrusted container images.
77
-
- Use rootless containers where possible to reduce impact scope.
78
-
- Restrict container `sysctl` configurations and disable host access to `/proc/sysrq-trigger` and
79
-
`/proc/sys/kernel/core_pattern` where feasible.
80
-
- Reinforce LSM enforcement and confirm AppArmor and SELinux profiles are correctly applied post-patch.
76
+
1. Use the `kubeconfig` file and `kubectl` tool to access your Palette enterprise or VerteX cluster. Refer to the
77
+
[Access Cluster with CLI](../../clusters/cluster-management/palette-webctl.md) guide for more information.
78
+
79
+
2. Check the image used by the `ingress-nginx-controller` DaemonSet in the `ingress-nginx` namespace.
1. Contact your Palette support representative to obtain the `airgap-pack-nginx` binary version `1.13.7`. Once obtained,
316
+
upload the `airgap-pack-nginx` binary to the registry. Follow the
317
+
[Usage Instructions](../../downloads/self-hosted-palette/additional-packs.md) guide for detailed steps on downloading
318
+
and installing the binary.
319
+
320
+
2. Log in to the Palette system console.
321
+
322
+
3. From the left main menu, select **Administration > Pack Registries**. Then, next to the registry, click the three-dot
323
+
button > **Sync**. Wait for the registry synchronization to complete.
324
+
325
+
4. Log in to the Palette console.
326
+
327
+
5. Update all cluster profiles currently using the affected version of the Nginx pack. Refer to the
328
+
[Update a Cluster Profile](../../profiles/cluster-profiles/modify-cluster-profiles/update-cluster-profile.md) guide
329
+
for instructions on how to update a cluster profile.
330
+
331
+
6. Apply the profile updates to all affected clusters. Refer to the
332
+
[Apply Profile Updates to Clusters](../../profiles/cluster-profiles/modify-cluster-profiles/update-cluster-profile.md#apply-profile-updates-to-clusters)
333
+
guide to learn how to apply profile updates to clusters.
1. Contact your Palette support representative to obtain the `airgap-pack-nginx` binary version `1.13.7`. Follow the
340
+
[Usage Instructions](../../downloads/palette-vertex/additional-packs.md) guide for detailed steps on downloading and
341
+
installing the binary.
342
+
343
+
2. Log in to the Palette VerteX system console.
344
+
345
+
3. From the left main menu, select **Administration > Pack Registries**. Then, next to the registry, click the three-dot
346
+
button > **Sync**. Wait for the registry synchronization to complete.
347
+
348
+
4. Log in to the Palette VerteX console.
349
+
350
+
5. Update all cluster profiles currently using the affected version of the Nginx pack. Refer to the
351
+
[Update a Cluster Profile](../../profiles/cluster-profiles/modify-cluster-profiles/update-cluster-profile.md) guide
352
+
for instructions on how to update a cluster profile.
353
+
354
+
6. Apply the profile updates to all affected clusters. Refer to the
355
+
[Apply Profile Updates to Clusters](../../profiles/cluster-profiles/modify-cluster-profiles/update-cluster-profile.md#apply-profile-updates-to-clusters)
356
+
guide to learn how to apply profile updates to clusters.
0 commit comments