Skip to main content
The Settings > Maintenance > Security Patches page in the Aviatrix Controller lists all available security patches and indicates whether or not they have been installed. It is expected that customers who upgrade to the latest release install any patches that are not currently installed, or only partially installed. The table below lists the available patches.

Applying a Security Patch

To apply a patch:
  1. Backup your Aviatrix Controller. For more information, see Controller Backup and Restore .
  2. Apply the security or software patch on the controller. From the Aviatrix Controller, navigate to Settings > Maintenance > SecurityPatches or SoftwarePatches and click on UpdateAvailablePatches. You should see the new patch in the display.
  3. Apply the patch by clicking on the icon on the right and selecting Apply Patch from the popup menu.
  4. Validate the update by clicking on the icon on the right and selecting Patch Status and scrolling down to bottom of page.
  5. Backup your Aviatrix Controller again to save the new configuration.

When to Apply Patches

Controllers Security Patch (01 Nov 21)

Subject: AVI-2021-0005 Apache Request Smuggling Vulnerability Security Patch. Issues: This patch addresses vulnerabilities fixed by Apache version 2.4.51. Aviatrix released new AMIs for AWS on 13 Oct 2021 to address vulnerabilities (CVE-2021-40438 and CVE-2021-33193). You are fully covered if you migrated your Controller to use the new AMIs mentioned in the AWS AMI image release notes, and you followed the instructions for migrating images . This patch will address the same issue without requiring a Controller migration. For Controllers running in AWS, Aviatrix recommends that you migrate your Controllers as instructed in migrating images . For Controllers running in cloud service providers other than AWS (Azure, GCP, etc.), you can apply this security patch. To apply the security patch:
  1. Secure a maintenance window and execute the following during the maintenance window.
  2. Go to your Controller (any version) management console.
  3. Go to Settings > Maintenance > Backup & Restore. Make sure you have a backup of your current settings.
  4. Go to Settings > Maintenance > Security Patches and click on “Update available patches”.
  5. From the list of patches, apply the “AVI-2021-0005 Apache Request Smuggling Vulnerability” patch.
  6. Back up your Controller again.
(CloudN standalone mode) To apply the security patch if you have CloudN running in a standalone mode, Aviatrix suggests you run the following in a maintenance window:
  1. Go to CloudN > Maintenance > Security Patches and click on “Update available patches”.
  2. Please make sure that CloudN has outbound access to 0.0.0.0/0 for ports 80 and 443 before applying the patch.
  3. From the list of patches, apply the “AVI-2021-0005 Apache Request Smuggling Vulnerability” patch.
(CloudN in CaaG mode) To apply the security patch if you have CloudN running in a CaaG mode, Aviatrix suggests you run the following during a maintenance window:
  1. Detach CaaG from the Transit Gateway.
  2. Deregister the CaaG Gateway.
  3. Reload the CloudN UI page.
  4. Go to CloudN > Maintenance > Security Patches and click on “Update available patches”.
  5. Please make sure that CloudN has outbound access to 0.0.0.0/0 for ports 80 and 443 before applying the patch.
  6. From the list of patches, apply the “AVI-2021-0005 Apache Request Smuggling Vulnerability” patch.
  7. Register CaaG back to the Controller.
  8. Attach CaaG back to the Transit Gateway.
Controller version 7.1.3956 is the last version that supports CloudN. CloudN is being replaced by Aviatrix Edge . For more information, contact your account team.