Skip to content

Commit d35a2f9

Browse files
authored
Release 14.3.36 (#52151)
1 parent b1dc9f0 commit d35a2f9

File tree

17 files changed

+113
-105
lines changed

17 files changed

+113
-105
lines changed

CHANGELOG.md

+8
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,13 @@
11
# Changelog
22

3+
## 14.3.36 (02/13/25)
4+
5+
### Security Fixes
6+
7+
* Fixed security issue with arbitrary file reads on SSH nodes. [#52139](https://github.com/gravitational/teleport/pull/52139)
8+
* Verify that cluster name of TLS peer certs matches the cluster name of the CA that issued it to prevent Auth bypasses. [#52133](https://github.com/gravitational/teleport/pull/52133)
9+
* Updated golang.org/x/crypto to v0.31.0 (CVE-2024-45337). [#50081](https://github.com/gravitational/teleport/pull/50081)
10+
311
## 14.3.34 (11/27/24)
412

513
* Fixed a bug in the `teleport-cluster` Helm chart that can cause token mount to fail when using ArgoCD. [#49071](https://github.com/gravitational/teleport/pull/49071)

Makefile

+1-1
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@
1111
# Stable releases: "1.0.0"
1212
# Pre-releases: "1.0.0-alpha.1", "1.0.0-beta.2", "1.0.0-rc.3"
1313
# Master/dev branch: "1.0.0-dev"
14-
VERSION=14.3.34
14+
VERSION=14.3.36
1515

1616
DOCKER_IMAGE ?= teleport
1717

api/version.go

+1-1
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

build.assets/macos/tsh/tsh.app/Contents/Info.plist

+2-2
Original file line numberDiff line numberDiff line change
@@ -19,13 +19,13 @@
1919
<key>CFBundlePackageType</key>
2020
<string>APPL</string>
2121
<key>CFBundleShortVersionString</key>
22-
<string>14.3.34</string>
22+
<string>14.3.36</string>
2323
<key>CFBundleSupportedPlatforms</key>
2424
<array>
2525
<string>MacOSX</string>
2626
</array>
2727
<key>CFBundleVersion</key>
28-
<string>14.3.34</string>
28+
<string>14.3.36</string>
2929
<key>DTCompiler</key>
3030
<string>com.apple.compilers.llvm.clang.1_0</string>
3131
<key>DTPlatformBuild</key>

build.assets/macos/tshdev/tsh.app/Contents/Info.plist

+2-2
Original file line numberDiff line numberDiff line change
@@ -17,13 +17,13 @@
1717
<key>CFBundlePackageType</key>
1818
<string>APPL</string>
1919
<key>CFBundleShortVersionString</key>
20-
<string>14.3.34</string>
20+
<string>14.3.36</string>
2121
<key>CFBundleSupportedPlatforms</key>
2222
<array>
2323
<string>MacOSX</string>
2424
</array>
2525
<key>CFBundleVersion</key>
26-
<string>14.3.34</string>
26+
<string>14.3.36</string>
2727
<key>DTCompiler</key>
2828
<string>com.apple.compilers.llvm.clang.1_0</string>
2929
<key>DTPlatformBuild</key>

examples/chart/teleport-cluster/Chart.yaml

+1-1
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
.version: &version "14.3.34"
1+
.version: &version "14.3.36"
22

33
name: teleport-cluster
44
apiVersion: v2

examples/chart/teleport-cluster/charts/teleport-operator/Chart.yaml

+1-1
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
.version: &version "14.3.34"
1+
.version: &version "14.3.36"
22

33
name: teleport-operator
44
apiVersion: v2

examples/chart/teleport-cluster/tests/__snapshot__/auth_clusterrole_test.yaml.snap

+2-2
Original file line numberDiff line numberDiff line change
@@ -8,8 +8,8 @@ adds operator permissions to ClusterRole:
88
app.kubernetes.io/instance: RELEASE-NAME
99
app.kubernetes.io/managed-by: Helm
1010
app.kubernetes.io/name: teleport-cluster
11-
app.kubernetes.io/version: 14.3.34
12-
helm.sh/chart: teleport-cluster-14.3.34
11+
app.kubernetes.io/version: 14.3.36
12+
helm.sh/chart: teleport-cluster-14.3.36
1313
teleport.dev/majorVersion: "14"
1414
name: RELEASE-NAME
1515
rules:

examples/chart/teleport-cluster/tests/__snapshot__/auth_config_test.yaml.snap

+2-2
Original file line numberDiff line numberDiff line change
@@ -1797,8 +1797,8 @@ sets clusterDomain on Configmap:
17971797
app.kubernetes.io/instance: RELEASE-NAME
17981798
app.kubernetes.io/managed-by: Helm
17991799
app.kubernetes.io/name: teleport-cluster
1800-
app.kubernetes.io/version: 14.3.34
1801-
helm.sh/chart: teleport-cluster-14.3.34
1800+
app.kubernetes.io/version: 14.3.36
1801+
helm.sh/chart: teleport-cluster-14.3.36
18021802
teleport.dev/majorVersion: "14"
18031803
name: RELEASE-NAME-auth
18041804
namespace: NAMESPACE

examples/chart/teleport-cluster/tests/__snapshot__/auth_deployment_test.yaml.snap

+5-5
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
should add an operator side-car when operator is enabled:
22
1: |
3-
image: public.ecr.aws/gravitational/teleport-operator:14.3.34
3+
image: public.ecr.aws/gravitational/teleport-operator:14.3.36
44
imagePullPolicy: IfNotPresent
55
livenessProbe:
66
httpGet:
@@ -41,7 +41,7 @@ should add an operator side-car when operator is enabled:
4141
- args:
4242
- --diag-addr=0.0.0.0:3000
4343
- --apply-on-startup=/etc/teleport/apply-on-startup.yaml
44-
image: public.ecr.aws/gravitational/teleport-distroless:14.3.34
44+
image: public.ecr.aws/gravitational/teleport-distroless:14.3.36
4545
imagePullPolicy: IfNotPresent
4646
lifecycle:
4747
preStop:
@@ -174,7 +174,7 @@ should set nodeSelector when set in values:
174174
- args:
175175
- --diag-addr=0.0.0.0:3000
176176
- --apply-on-startup=/etc/teleport/apply-on-startup.yaml
177-
image: public.ecr.aws/gravitational/teleport-distroless:14.3.34
177+
image: public.ecr.aws/gravitational/teleport-distroless:14.3.36
178178
imagePullPolicy: IfNotPresent
179179
lifecycle:
180180
preStop:
@@ -271,7 +271,7 @@ should set resources when set in values:
271271
- args:
272272
- --diag-addr=0.0.0.0:3000
273273
- --apply-on-startup=/etc/teleport/apply-on-startup.yaml
274-
image: public.ecr.aws/gravitational/teleport-distroless:14.3.34
274+
image: public.ecr.aws/gravitational/teleport-distroless:14.3.36
275275
imagePullPolicy: IfNotPresent
276276
lifecycle:
277277
preStop:
@@ -357,7 +357,7 @@ should set securityContext when set in values:
357357
- args:
358358
- --diag-addr=0.0.0.0:3000
359359
- --apply-on-startup=/etc/teleport/apply-on-startup.yaml
360-
image: public.ecr.aws/gravitational/teleport-distroless:14.3.34
360+
image: public.ecr.aws/gravitational/teleport-distroless:14.3.36
361361
imagePullPolicy: IfNotPresent
362362
lifecycle:
363363
preStop:

examples/chart/teleport-cluster/tests/__snapshot__/proxy_config_test.yaml.snap

+2-2
Original file line numberDiff line numberDiff line change
@@ -567,8 +567,8 @@ sets clusterDomain on Configmap:
567567
app.kubernetes.io/instance: RELEASE-NAME
568568
app.kubernetes.io/managed-by: Helm
569569
app.kubernetes.io/name: teleport-cluster
570-
app.kubernetes.io/version: 14.3.34
571-
helm.sh/chart: teleport-cluster-14.3.34
570+
app.kubernetes.io/version: 14.3.36
571+
helm.sh/chart: teleport-cluster-14.3.36
572572
teleport.dev/majorVersion: "14"
573573
name: RELEASE-NAME-proxy
574574
namespace: NAMESPACE

examples/chart/teleport-cluster/tests/__snapshot__/proxy_deployment_test.yaml.snap

+16-16
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,8 @@ sets clusterDomain on Deployment Pods:
1111
app.kubernetes.io/instance: RELEASE-NAME
1212
app.kubernetes.io/managed-by: Helm
1313
app.kubernetes.io/name: teleport-cluster
14-
app.kubernetes.io/version: 14.3.34
15-
helm.sh/chart: teleport-cluster-14.3.34
14+
app.kubernetes.io/version: 14.3.36
15+
helm.sh/chart: teleport-cluster-14.3.36
1616
teleport.dev/majorVersion: "14"
1717
name: RELEASE-NAME-proxy
1818
namespace: NAMESPACE
@@ -26,16 +26,16 @@ sets clusterDomain on Deployment Pods:
2626
template:
2727
metadata:
2828
annotations:
29-
checksum/config: 86bc053300d968e11b90f5fc900381e8309275c6976b95ee7e5463abd8750dcd
29+
checksum/config: 5f89f5a4075c5ca9358c36cfe06fd7d07787f7ff2b4484c434a6e08f7af7e256
3030
kubernetes.io/pod: test-annotation
3131
kubernetes.io/pod-different: 4
3232
labels:
3333
app.kubernetes.io/component: proxy
3434
app.kubernetes.io/instance: RELEASE-NAME
3535
app.kubernetes.io/managed-by: Helm
3636
app.kubernetes.io/name: teleport-cluster
37-
app.kubernetes.io/version: 14.3.34
38-
helm.sh/chart: teleport-cluster-14.3.34
37+
app.kubernetes.io/version: 14.3.36
38+
helm.sh/chart: teleport-cluster-14.3.36
3939
teleport.dev/majorVersion: "14"
4040
spec:
4141
affinity:
@@ -44,7 +44,7 @@ sets clusterDomain on Deployment Pods:
4444
containers:
4545
- args:
4646
- --diag-addr=0.0.0.0:3000
47-
image: public.ecr.aws/gravitational/teleport-distroless:14.3.34
47+
image: public.ecr.aws/gravitational/teleport-distroless:14.3.36
4848
imagePullPolicy: IfNotPresent
4949
lifecycle:
5050
preStop:
@@ -105,7 +105,7 @@ sets clusterDomain on Deployment Pods:
105105
- wait
106106
- no-resolve
107107
- RELEASE-NAME-auth-v13.NAMESPACE.svc.test.com
108-
image: public.ecr.aws/gravitational/teleport-distroless:14.3.34
108+
image: public.ecr.aws/gravitational/teleport-distroless:14.3.36
109109
name: wait-auth-update
110110
serviceAccountName: RELEASE-NAME-proxy
111111
terminationGracePeriodSeconds: 60
@@ -137,7 +137,7 @@ should provision initContainer correctly when set in values:
137137
- wait
138138
- no-resolve
139139
- RELEASE-NAME-auth-v13.NAMESPACE.svc.cluster.local
140-
image: public.ecr.aws/gravitational/teleport-distroless:14.3.34
140+
image: public.ecr.aws/gravitational/teleport-distroless:14.3.36
141141
name: wait-auth-update
142142
- args:
143143
- echo test
@@ -194,7 +194,7 @@ should set nodeSelector when set in values:
194194
containers:
195195
- args:
196196
- --diag-addr=0.0.0.0:3000
197-
image: public.ecr.aws/gravitational/teleport-distroless:14.3.34
197+
image: public.ecr.aws/gravitational/teleport-distroless:14.3.36
198198
imagePullPolicy: IfNotPresent
199199
lifecycle:
200200
preStop:
@@ -255,7 +255,7 @@ should set nodeSelector when set in values:
255255
- wait
256256
- no-resolve
257257
- RELEASE-NAME-auth-v13.NAMESPACE.svc.cluster.local
258-
image: public.ecr.aws/gravitational/teleport-distroless:14.3.34
258+
image: public.ecr.aws/gravitational/teleport-distroless:14.3.36
259259
name: wait-auth-update
260260
nodeSelector:
261261
environment: security
@@ -306,7 +306,7 @@ should set resources when set in values:
306306
containers:
307307
- args:
308308
- --diag-addr=0.0.0.0:3000
309-
image: public.ecr.aws/gravitational/teleport-distroless:14.3.34
309+
image: public.ecr.aws/gravitational/teleport-distroless:14.3.36
310310
imagePullPolicy: IfNotPresent
311311
lifecycle:
312312
preStop:
@@ -374,7 +374,7 @@ should set resources when set in values:
374374
- wait
375375
- no-resolve
376376
- RELEASE-NAME-auth-v13.NAMESPACE.svc.cluster.local
377-
image: public.ecr.aws/gravitational/teleport-distroless:14.3.34
377+
image: public.ecr.aws/gravitational/teleport-distroless:14.3.36
378378
name: wait-auth-update
379379
serviceAccountName: RELEASE-NAME-proxy
380380
terminationGracePeriodSeconds: 60
@@ -407,7 +407,7 @@ should set securityContext for initContainers when set in values:
407407
containers:
408408
- args:
409409
- --diag-addr=0.0.0.0:3000
410-
image: public.ecr.aws/gravitational/teleport-distroless:14.3.34
410+
image: public.ecr.aws/gravitational/teleport-distroless:14.3.36
411411
imagePullPolicy: IfNotPresent
412412
lifecycle:
413413
preStop:
@@ -475,7 +475,7 @@ should set securityContext for initContainers when set in values:
475475
- wait
476476
- no-resolve
477477
- RELEASE-NAME-auth-v13.NAMESPACE.svc.cluster.local
478-
image: public.ecr.aws/gravitational/teleport-distroless:14.3.34
478+
image: public.ecr.aws/gravitational/teleport-distroless:14.3.36
479479
name: wait-auth-update
480480
securityContext:
481481
allowPrivilegeEscalation: false
@@ -515,7 +515,7 @@ should set securityContext when set in values:
515515
containers:
516516
- args:
517517
- --diag-addr=0.0.0.0:3000
518-
image: public.ecr.aws/gravitational/teleport-distroless:14.3.34
518+
image: public.ecr.aws/gravitational/teleport-distroless:14.3.36
519519
imagePullPolicy: IfNotPresent
520520
lifecycle:
521521
preStop:
@@ -583,7 +583,7 @@ should set securityContext when set in values:
583583
- wait
584584
- no-resolve
585585
- RELEASE-NAME-auth-v13.NAMESPACE.svc.cluster.local
586-
image: public.ecr.aws/gravitational/teleport-distroless:14.3.34
586+
image: public.ecr.aws/gravitational/teleport-distroless:14.3.36
587587
name: wait-auth-update
588588
securityContext:
589589
allowPrivilegeEscalation: false

examples/chart/teleport-kube-agent/Chart.yaml

+1-1
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
.version: &version "14.3.34"
1+
.version: &version "14.3.36"
22

33
name: teleport-kube-agent
44
apiVersion: v2

0 commit comments

Comments
 (0)