Where would we find out if a cloud provider vulnerability is mitigated in SAS Viya Azure Pay-As-You-Go?
Specific to my scenario, I am running V.04.00M0P011723 and the vulnerability of concern is CVE-2023-29332, Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability.
I assume that the SAS Viya Azure Pay-As-You-Go managed version will not make this update automatically after restart. So would it be necessary to create a new managed deployment from azure market place once I confirm a newer release has this vulnerability mitigated?
Hi @balbarka -
Based on your installed version of SAS Viya, I believe you are running on AKS major version 1.24, which is not vulnerable to CVE-2023-29332:
You can confirm you AKS version in the Azure portal by navigating to your managed application and clicking on the "Parameters and Outputs" pane. At the bottom, you should see a value called kubernetesVersion in the outputs that shows the AKS version that was deployed.
Please let me know if you have any further questions or concerns.
Best regards,
Rich
Hi @balbarka -
Based on your installed version of SAS Viya, I believe you are running on AKS major version 1.24, which is not vulnerable to CVE-2023-29332:
You can confirm you AKS version in the Azure portal by navigating to your managed application and clicking on the "Parameters and Outputs" pane. At the bottom, you should see a value called kubernetesVersion in the outputs that shows the AKS version that was deployed.
Please let me know if you have any further questions or concerns.
Best regards,
Rich
Thanks @rich_sas ! Confirmed as described:
Nearly 200 sessions are now available on demand in the Innovate Hub.
Watch Now →