RHSA-2022:0687: Moderate: OpenShift API for Data Protection (OADP) 1.0.1 security and bug fix update
OpenShift API for Data Protection (OADP) enables you to back up and restore application resources, persistent volume data, and internal container images to external backup storage. OADP enables both file system-based and snapshot-based backups for persistent volumes.Security Fix(es): ulikunitz/xz: Infinite loop in readUvarint allows for denial of service (CVE-2021-29482) opencontainers: OCI manifest and index parsing confusion (CVE-2021-41190) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenShift API for Data Protection (OADP)to a version that resolves this vulnerability.Fixed in 1.0.1
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0687?
The severity of RHSA-2022:0687 is classified as critical.
How do I fix RHSA-2022:0687?
To fix RHSA-2022:0687, you need to update your OpenShift API for Data Protection to the latest patched version.
What software is affected by RHSA-2022:0687?
RHSA-2022:0687 affects the OpenShift API for Data Protection and its associated components.
What vulnerabilities are addressed in RHSA-2022:0687?
RHSA-2022:0687 addresses multiple security vulnerabilities that can lead to unauthorized access to backup resources.
How can I verify if my system is vulnerable to RHSA-2022:0687?
You can verify if your system is vulnerable to RHSA-2022:0687 by checking the version of the OpenShift API for Data Protection installed on your system.