Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

RedHat: RHSA-2022-7262-01 Moderate: OpenShift Network Vulnerability Exploit

red hat
Calendar Grey October 31, 2022
Dist Redhat Esm H88
The OpenShift API has alerted users to possible Denial of Service vulnerabilities tied to Data Protection features. Admins should review settings to reduce risks and ensure service stability
OpenShift API for Data Protection (OADP) 1.0.5 is now available

Solution

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Summary

OpenShift API for Data Protection (OADP) enables you to back up and restore application resources, persistent volume data, and internal container images to external backup storage. OADP enables both file system-based and snapshot-based backups for persistent volumes.
Security Fix(es):
* prometheus/client_golang: Denial of service using InstrumentHandlerCounter (CVE-2022-21698)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2022-21698 https://access.redhat.com/security/cve/CVE-2022-34903 https://access.redhat.com/security/cve/CVE-2022-40674 https://access.redhat.com/security/updates/classification/#moderate

Package List


Advisory ID: RHSA-2022:7261-01
Product: OpenShift API for Data Protection
Issue date: 2022-10-31

Topic

OpenShift API for Data Protection (OADP) 1.0.5 is now available.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Bugs Fixed

2045880 - CVE-2022-21698 prometheus/client_golang: Denial of service using InstrumentHandlerCounter

5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects):

OADP-801 - Openshift plugin does not add Migration Plan labels on all resources

OADP-812 - openshift-adp-controller-manager should not continuously log once dpa reaches reconciled

OADP-823 - Check OADP and Openshift Versions and warn / error on compatibility

OADP-829 - Registry pod going in crashloopbackoff state

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here