RHSA-2024:3790: Moderate: OpenShift API for Data Protection (OADP) 1.3.2 security and bug fix update
Moderate: OpenShift API for Data Protection (OADP) 1.3.2 security and bug fix update
Other sources
OpenShift API for Data Protection (OADP) enables you to back up and restore application resources, persistent volume data, and internal container images to external backup storage. OADP enables both file system-based and snapshot-based backups for persistent volumes.Security Fix(es) from Bugzilla: golang: net/http: memory exhaustion in Request.ParseMultipartForm (CVE-2023-45290) golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect (CVE-2023-45289) golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm (CVE-2024-24783) golang: net/mail: comments in display names are incorrectly handled (CVE-2024-24784) golang: html/template: errors returned from MarshalJSON methods may break template escaping (CVE-2024-24785) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:3790?
The severity of RHSA-2024:3790 is categorized as Moderate.
How do I fix RHSA-2024:3790?
To fix RHSA-2024:3790, ensure that you update the OpenShift API for Data Protection to version 1.3.2 or later.
Which products are affected by RHSA-2024:3790?
RHSA-2024:3790 affects multiple products including Red Hat OpenShift API for Data Protection for IBM Z and LinuxONE and for ARM 64.
What does RHSA-2024:3790 address?
RHSA-2024:3790 addresses security vulnerabilities and includes bug fixes for the OpenShift API for Data Protection.
When was RHSA-2024:3790 released?
RHSA-2024:3790 was released as a security and bug fix update for the OpenShift API for Data Protection.