Applying a Security Patch
To apply a patch:- Backup your Aviatrix Controller. For more information, see Controller Backup and Restore .
- Apply the security or software patch on the controller. From the Aviatrix Controller, navigate to Settings > Maintenance > SecurityPatches or SoftwarePatches and click on UpdateAvailablePatches. You should see the new patch in the display.
- Apply the patch by clicking on the icon on the right and selecting Apply Patch from the popup menu.
- Validate the update by clicking on the icon on the right and selecting Patch Status and scrolling down to bottom of page.
- Backup your Aviatrix Controller again to save the new configuration.
When to Apply Patches
Controllers Security Patch (01 Nov 21)
Subject: AVI-2021-0005 Apache Request Smuggling Vulnerability Security Patch. Issues: This patch addresses vulnerabilities fixed by Apache version 2.4.51. Aviatrix released new AMIs for AWS on 13 Oct 2021 to address vulnerabilities (CVE-2021-40438 and CVE-2021-33193). You are fully covered if you migrated your Controller to use the new AMIs mentioned in the AWS AMI image release notes, and you followed the instructions for migrating images . This patch will address the same issue without requiring a Controller migration. For Controllers running in AWS, Aviatrix recommends that you migrate your Controllers as instructed in migrating images . For Controllers running in cloud service providers other than AWS (Azure, GCP, etc.), you can apply this security patch. To apply the security patch:- Secure a maintenance window and execute the following during the maintenance window.
- Go to your Controller (any version) management console.
- Go to Settings > Maintenance > Backup & Restore. Make sure you have a backup of your current settings.
- Go to Settings > Maintenance > Security Patches and click on “Update available patches”.
- From the list of patches, apply the “AVI-2021-0005 Apache Request Smuggling Vulnerability” patch.
- Back up your Controller again.
- Go to CloudN > Maintenance > Security Patches and click on “Update available patches”.
- Please make sure that CloudN has outbound access to 0.0.0.0/0 for ports 80 and 443 before applying the patch.
- From the list of patches, apply the “AVI-2021-0005 Apache Request Smuggling Vulnerability” patch.
- Detach CaaG from the Transit Gateway.
- Deregister the CaaG Gateway.
- Reload the CloudN UI page.
- Go to CloudN > Maintenance > Security Patches and click on “Update available patches”.
- Please make sure that CloudN has outbound access to 0.0.0.0/0 for ports 80 and 443 before applying the patch.
- From the list of patches, apply the “AVI-2021-0005 Apache Request Smuggling Vulnerability” patch.
- Register CaaG back to the Controller.
- Attach CaaG back to the Transit Gateway.
Controller version 7.1.3956 is the last version that supports CloudN. CloudN
is being replaced by
Aviatrix Edge
. For more information, contact your account team.