RHSA-2024:4982: Important: OpenShift API for Data Protection (OADP) 1.3.3 security and bug fix update
Important: OpenShift API for Data Protection (OADP) 1.3.3 security and bug fix update
Other sources
OpenShift API for Data Protection (OADP) enables you to back up and restore application resources, persistent volume data, and internal container images to external backup storage. OADP enables both file system-based and snapshot-based backups for persistent volumes.Security Fix(es) from Bugzilla: golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS (CVE-2023-45288) golang: net: malformed DNS message can cause infinite loop (CVE-2024-24788) golang: archive/zip: Incorrect handling of certain ZIP files (CVE-2024-24789) golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses (CVE-2024-24790) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:4982?
The severity of RHSA-2024:4982 is categorized as important.
How do I fix RHSA-2024:4982?
To fix RHSA-2024:4982, you should update the OpenShift API for Data Protection to the latest version available.
Which software is affected by RHSA-2024:4982?
RHSA-2024:4982 affects several versions of the OpenShift API for Data Protection across different platforms, including IBM Z, LinuxONE, ARM 64, and IBM Power.
What type of issues does RHSA-2024:4982 address?
RHSA-2024:4982 addresses both security vulnerabilities and bug fixes in the OpenShift API for Data Protection.
Is there a known exploit for RHSA-2024:4982?
As of the advisory, there were no publicly available exploits reported for the vulnerabilities in RHSA-2024:4982.