RHSA-2023:5314: Moderate: OpenShift API for Data Protection (OADP) 1.1.6 security and bug fix update
Moderate: OpenShift API for Data Protection (OADP) 1.1.6 security and bug fix update
Other sources
OpenShift API for Data Protection (OADP) enables you to back up and restore application resources, persistent volume data, and internal container images to external backup storage. OADP enables both file system-based and snapshot-based backups for persistent volumes.Security Fix(es): prometheus/clientgolang: Denial of service using InstrumentHandlerCounter (CVE-2022-21698) net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723) distribution/distribution: DoS from malicious API request (CVE-2023-2253) golang: crypto/internal/nistec: specific unreduced P-256 scalars produce incorrect results (CVE-2023-24532) containerd: Supplementary groups are not set up properly (CVE-2023-25173) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:5314?
The severity of RHSA-2023:5314 is moderate.
What is the update for RHSA-2023:5314?
RHSA-2023:5314 is a security and bug fix update for OpenShift API for Data Protection (OADP) version 1.1.6.
What software is affected by RHSA-2023:5314?
Red Hat OpenShift API for Data Protection (OADP) is affected by RHSA-2023:5314.
Where can I find more information about RHSA-2023:5314?
You can find more information about RHSA-2023:5314 in the Red Hat Knowledgebase and related bugzilla links: [access.redhat.com/errata/RHSA-2023:5314](https://access.redhat.com/errata/RHSA-2023:5314), [bugzilla.redhat.com/show_bug.cgi?id=2045880](https://bugzilla.redhat.com/show_bug.cgi?id=2045880), [bugzilla.redhat.com/show_bug.cgi?id=2174485](https://bugzilla.redhat.com/show_bug.cgi?id=2174485).
Is there a fix available for RHSA-2023:5314?
Yes, RHSA-2023:5314 provides a fix for the identified security vulnerabilities and bugs.