Announcing Istio 1.2.5
Istio 1.2.5 patch release.
We’re pleased to announce the availability of Istio 1.2.5. Please see below for what’s changed.
BEFORE YOU UPGRADE
Things to know and prepare before upgrading.
Download and install this release.
Visit the documentation for this release.
Inspect the full set of source code changes.
Following the previous fixes for the security vulnerabilities described in ISTIO-SECURITY-2019-003 and ISTIO-SECURITY-2019-004, we are now addressing the internal control plane communication surface. These security fixes were not available at the time of our previous security release, and we considered the control plane gRPC surface to be harder to exploit.
You can find the gRPC vulnerability fix description on their mailing list (c.f. HTTP/2 Security Vulnerabilities).
- Fix an Envoy bug that breaks
java.net.http.HttpClientand other clients that attempt to upgrade from
Upgrade: h2cheader (Issue 16391).
- Fix a memory leak on send timeout (Issue 15876).