First published: Mon Feb 28 2022(Updated: )
OpenShift API for Data Protection (OADP) enables you to back up and restore application resources, persistent volume data, and internal container images to external backup storage. OADP enables both file system-based and snapshot-based backups for persistent volumes.<br>Security Fix(es):<br><li> ulikunitz/xz: Infinite loop in readUvarint allows for denial of service (CVE-2021-29482)</li> <li> opencontainers: OCI manifest and index parsing confusion (CVE-2021-41190)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:0687 is classified as critical.
To fix RHSA-2022:0687, you need to update your OpenShift API for Data Protection to the latest patched version.
RHSA-2022:0687 affects the OpenShift API for Data Protection and its associated components.
RHSA-2022:0687 addresses multiple security vulnerabilities that can lead to unauthorized access to backup resources.
You can verify if your system is vulnerable to RHSA-2022:0687 by checking the version of the OpenShift API for Data Protection installed on your system.