Angaben zum Datum
Datum aus der Quelle.
Erstmals gesehen am .
Portainer 2.45.2 LTS mit Sicherheitsfixes und neuen Node-Spalten
Portainer 2.45.2 LTS behebt mehrere Sicherheitsprobleme (Umgehung der Einstellung „Hide bind mounts for non-administrators“, vorzeitiges Entfernen von Kubernetes-Namespace-Daten bei abgelehnter Löschung, fehlende TLS-Zertifikatsprüfung bei In-Cluster-HTTPS-Verbindungen) und ergänzt in der Kubernetes-Node-Liste eine Node-group-Spalte sowie optionale Spalten für Instance type, Labels und Taints.
Known issues
- On Async Edge environments, an invalid update schedule date can be displayed when browsing a snapshot
Known issues with Podman support
- Podman environments aren't supported by auto-onboarding script
- It's not possible to add Podman environments via socket, when running a Portainer server on Docker (and vice versa)
- Support for only CentOS 9, Podman 5 rootful
Changes
Security
- Fixed a bypass of the "Hide bind mounts for non-administrators" setting. When it is enabled, Compose files deployed by non-administrators can no longer reference host files outside the stack directory (for example in configs, secrets or env_file), and include is disabled for them.
- Fixed a denied, failed or dry-run Kubernetes namespace deletion still removing Portainer's namespace access policies, stack records and registry bindings. These records are now removed only after Kubernetes accepts the deletion
- Fixed in-cluster HTTPS connections to the Kubernetes API server skipping TLS certificate verification during stack deploy and removal, on both the server and the agent
Features
- Added a Node group column to the Kubernetes cluster node list for clusters using EKS, GKE, AKS, Karpenter or kops node pools, plus optional Instance type, Labels and Taints columns that can be turned on from the column menu