Red Hat Security Advisory: OpenShift API for Data Protection (OADP) 1.3.2 security and bug fix update
🔗 CVE IDs covered (5)
📋 Description
CVE-2023-45289 — golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect CVE-2023-45290 — golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm CVE-2024-24783 — golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm CVE-2024-24784 — golang: net/mail: comments in display names are incorrectly handled CVE-2024-24785 — golang: html/template: errors returned from MarshalJSON methods may break template escaping
🎯 Affected products45
- 9Base-OADP-1.3
- oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:1e45e4f340caa82ec2c6bce6659c021220ba410bfe42e98f66d22efed052c520_arm64 as a component of 9Base-OADP-1.3
- oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:622e0c00270975968e9929b97e08e04f86340fd00636cb1a7282d2192184821f_amd64 as a component of 9Base-OADP-1.3
- oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:8c6b6d0784832bdf2813202be41db91fb3ad3f614a20f25c1f04d5d8bdb0ca21_s390x as a component of 9Base-OADP-1.3
- oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:8ceef07e495e0d66a031c838ca127ee7afa49307cb035097de4f0cfaf5fdc6bd_ppc64le as a component of 9Base-OADP-1.3
- oadp/oadp-mustgather-rhel9@sha256:62ca3bbc716f21cf96e8356349e6c789e00c89f809af6ab3432620dbdee07928_ppc64le as a component of 9Base-OADP-1.3
- oadp/oadp-mustgather-rhel9@sha256:653f39884d3d14e7eaa8ef3b75eda2298136c14f1dad0dc7ff3a8c96921a31f3_arm64 as a component of 9Base-OADP-1.3
- oadp/oadp-mustgather-rhel9@sha256:c1f53f2fec4aa372c67355edb7fe282d260958ad6873964d4c6a639c8db5b7ea_amd64 as a component of 9Base-OADP-1.3
- oadp/oadp-mustgather-rhel9@sha256:dde9a3cd19d382b529b3853618cb9522bd1811fa974292d15794cc081a9a20a6_s390x as a component of 9Base-OADP-1.3
- oadp/oadp-operator-bundle@sha256:138a4a5e6b435879c89d62e817db5a4bb0ac6337ec8324cec2dd9b6b94b7160c_arm64 as a component of 9Base-OADP-1.3
- oadp/oadp-operator-bundle@sha256:31052ac430ba2eb25ea301b15022a72779509632b11bb8f9d82a03a714964337_amd64 as a component of 9Base-OADP-1.3
- oadp/oadp-operator-bundle@sha256:46c52c72ec9f756bd3b79839db093de7b5ed3fe7ca2f925ad9330809cc3586a4_ppc64le as a component of 9Base-OADP-1.3
- oadp/oadp-operator-bundle@sha256:f77ebbf03b4d90743c258475ee9bffb3f05365a80788ceb3bbecc66675638100_s390x as a component of 9Base-OADP-1.3
- oadp/oadp-rhel9-operator@sha256:12cbe6f62f60c43feee7909510c706f9acbfef480303a78510f9764e6828b490_ppc64le as a component of 9Base-OADP-1.3
- oadp/oadp-rhel9-operator@sha256:82efc7bdd4eca653a235910722945b79387bc0e16075fa17a88707dfae516695_s390x as a component of 9Base-OADP-1.3
- oadp/oadp-rhel9-operator@sha256:c9bc0666a1410e813995a3be66fbd8196546f17257686343246fefd554cf2307_amd64 as a component of 9Base-OADP-1.3
- oadp/oadp-rhel9-operator@sha256:ff6fe0049cb1e5cc14d822df60f7c031b2c0202c1637efa08f280ebf2b235a28_arm64 as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-aws-rhel9@sha256:7e082176754dcfd059787fde99612d5708f592aa62a44fc30eaa2e47fccc5454_ppc64le as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-aws-rhel9@sha256:c249c245846076d49b3c386721c033739a7632ccc980e58bfbb1c3f1e4f9eb8a_s390x as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-aws-rhel9@sha256:e37f786f5bebcb8abef8570827c1887d7c021f704262e8494f8db7ac6877ef05_arm64 as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-aws-rhel9@sha256:f89dc5141b4c7c3bf4288d26462595262f2cbec45a86c62972f148489beb8129_amd64 as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-csi-rhel9@sha256:533f28f0301c108fd06e251a1d0f6bd061dafc1046fecdf455efce78ec7f0837_ppc64le as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-csi-rhel9@sha256:5fd0e06c0a8910aa9a1f18bf56bec90e346e44c30ac37a9fa55f995103eee56d_s390x as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-csi-rhel9@sha256:98617a1c636cbf2c9d8809288d1209a3f5ffc9a164764c5fc92d96ee7848e0a4_arm64 as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-csi-rhel9@sha256:a9ca63e75637e38636cfd4169bf152430af95c633f7383362215fe5083e01d51_amd64 as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:0ac64b4585de1fafd1dce471c5b9c9aa26ca2c047971d1e1e90017ae809661dc_arm64 as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:5c99638af1e9043b3bb06da2eaafdfb28254cb0a19925cfa6a537d26cd45aa3c_s390x as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:8236a27d95b6b3e4d450991de713539c64fdefe01aa2471ad77ecbb2824096c7_ppc64le as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:904f0edd8865ae4d7f1409556c461ae018926aa7ca860851b5dc3e2eaa9ddc6d_amd64 as a component of 9Base-OADP-1.3
- oadp/oadp-velero-plugin-for-microsoft-azure-rhel9@sha256:17e4230100c33315a5283460fa619147af2afe77c206d260fedb918d15984648_amd64 as a component of 9Base-OADP-1.3
- +15 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2024:3790
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268017
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268018
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268019
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268021
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268022
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_3790.json