Releases: wallarm/ingress
Releases · wallarm/ingress
5.2.12+upstream4.11.3
- Fixed controller vulnerability CVE-2024-45338
5.2.11+upstream4.11.3
- Fixed vulnerabilities: CVE-2024-45337, CVE-2024-45338
- [APIFW] Version bumped to v0.8.6
- [WCLI] Fixed an issue where some requests were processed unsuccessfully, potentially affecting API Sessions, Credential Stuffing, and API Abuse Prevention
5.2.2+upstream4.11.3
- Re-apply fix for IC vulnerability GHSA-c5pj-mqfh-rvc3
5.2.1+upstream4.11.3
-
NGINX IC Upgraded to Community version 1.11.3, aligning with the upstream Helm chart version 4.11.3
-
Breaking changes introduced by the Community Ingress NGINX Controller upgrade:
- Discontinued support for Opentracing and Zipkin modules, now only supporting Opentelemetry
- Dropped support for PodSecurityPolicy
-
Compatibility extended up to Kubernetes version 1.30
-
Updated to NGINX 1.25.5
-
New $wallarm_attack_point_list and $wallarm_attack_stamp_list variables for extended logging
- These variables log parameters containing malicious payloads and attack sign IDs enabling advanced debugging of Node behavior.
-
Minor bug fixes
4.10.14+upstream4.9.0
- [bug fix] wallarm_attack_type / wallarm_attack_type_list NGINX variables now properly show APIFW attacks
- APIFW version 0.8.3
- [bug fix] Introduced a way to illuminate the possibility for attackers to bypass APIFW protection
- added new APIFW configurable parameters in the helm chart (Description)
5.1.1+upstream4.9.0
- Fix IC vulnerability GHSA-c5pj-mqfh-rvc3
- [bug fix] Fixed issues with processing Wallarm status without requests in wcli
5.1.0+upstream4.9.0
What's Changed
- Over-limit events improvements
- APIFW version 0.8.3
- [bug fix] Introduced a way to illuminate the possibility for attackers to bypass APIFW protection
- Added new APIFW configurable parameters in the helm chart (Description)
- wallarm_attack_type / wallarm_attack_type_list NGINX variables now properly show APIFW attacks
- [init container] Reduced memory usage during node registration
- [bug fix]Wallarm solution turn on/off switch in Helm values now triggers pod redeployment properly to avoid unnecessary containers during the Helm upgrade process
4.10.13+upstream4.9.0
- Fixed memory leak on duplicate response headers in libproton (initially introduced in 4.8)
- Fixed memory leak in libwacl on IP addresses that are not in acldb but have known source (initially introduced in 4.8)
- Backported API Discovery fix of errors on missing status code
5.0.3+upstream4.9.0
- Added support for customizing sensitive data detection in API Discovery
- Fixed memory leak on duplicate response headers in libproton
- Fixed memory leak related to IP addresses that are not in IP lists but have known source
- Go version bumped to 1.22.7
- opencontainers/runc version bumped to 1.1.14
5.0.2+upstream4.9.0
- fixed installation fails without AAS subscription
- fixed export attack delay metric