From a219f9fb3f229f1d033e36d53e6e8fb0a93a06eb Mon Sep 17 00:00:00 2001 From: Adam Stephens Date: Thu, 19 Sep 2024 17:03:47 -0400 Subject: [PATCH] envoy: 1.30.5 -> 1.30.6 https://github.com/envoyproxy/envoy/releases/tag/v1.30.6 CVE-2024-45808: Malicious log injection via access logs CVE-2024-45806: Potential manipulate x-envoy headers from external sources CVE-2024-45809: Jwt filter crash in the clear route cache with remote JWKs CVE-2024-45810: Envoy crashes for LocalReply in http async client --- pkgs/servers/http/envoy/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/servers/http/envoy/default.nix b/pkgs/servers/http/envoy/default.nix index 77e81cfed49d..559ed5ef7ecb 100644 --- a/pkgs/servers/http/envoy/default.nix +++ b/pkgs/servers/http/envoy/default.nix @@ -24,9 +24,9 @@ let # However, the version string is more useful for end-users. # These are contained in a attrset of their own to make it obvious that # people should update both. - version = "1.30.5"; - rev = "20d3fc67fb757d7d7a644e0e0bfc3988b1df56ab"; - hash = "sha256-uogckAaP+eumY1GZw2+T3CusLE0gR2VEV96/lroQ6+g="; + version = "1.30.6"; + rev = "810bfcb8cae456e3a5e6541a0ee853185e2586f7"; + hash = "sha256-71UCctIfhMIevj6Wjy+E07IOe9qHSUgKwqzvFtBAf2k="; }; # these need to be updated for any changes to fetchAttrs