This update for containerized-data-importer fixes the following issues:
Update to version 1.64.0.
Security issues fixed:
- CVE-2024-28180: improper handling of highly compressed data (bsc#1235204).
- CVE-2024-45338: denial of service due to non-linear parsing of case-insensitive content (bsc#1235365).
- CVE-2025-22868: unexpected memory consumption during token parsing in golang.org/x/oauth2 (bsc#1239205).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-317=1
- openSUSE Leap 16.0:
containerized-data-importer-api-1.64.0-160000.1.1
containerized-data-importer-cloner-1.64.0-160000.1.1
containerized-data-importer-controller-1.64.0-160000.1.1
containerized-data-importer-importer-1.64.0-160000.1.1
containerized-data-importer-manifests-1.64.0-160000.1.1
containerized-data-importer-operator-1.64.0-160000.1.1
containerized-data-importer-uploadproxy-1.64.0-160000.1.1
containerized-data-importer-uploadserver-1.64.0-160000.1.1
obs-service-cdi_containers_meta-1.64.0-160000.1.1
* bsc#1235204
* bsc#1235365
* bsc#1239205
References:
* https://www.suse.com/security/cve/CVE-2024-28180.html
* https://www.suse.com/security/cve/CVE-2024-45338.html
* https://www.suse.com/security/cve/CVE-2025-22868.html
Get the latest Linux and open source security news straight to your inbox.