{"id":34161,"date":"2022-11-28T20:30:23","date_gmt":"2022-11-28T17:30:23","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/170027\/RHSA-2022-8634-01.txt"},"modified":"2022-11-30T08:48:10","modified_gmt":"2022-11-30T05:18:10","slug":"red-hat-security-advisory-2022-8634-01","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/red-hat-security-advisory-2022-8634-01\/","title":{"rendered":"Red Hat Security Advisory 2022-8634-01"},"content":{"rendered":"<p style=\"text-align: left;\">&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>\nHash: SHA256<\/p>\n<p style=\"text-align: left;\">====================================================================<br \/>\nRed Hat Security Advisory<\/p>\n<p style=\"text-align: left;\">Synopsis: Moderate: OpenShift API for Data Protection (OADP) 1.1.1 security and bug fix update<br \/>\nAdvisory ID: RHSA-2022:8634-01<br \/>\nProduct: OpenShift API for Data Protection<br \/>\nAdvisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:8634<br \/>\nIssue date: 2022-11-28<br \/>\nCVE Names: CVE-2020-35525 CVE-2020-35527 CVE-2022-2509<br \/>\nCVE-2022-3515 CVE-2022-27191 CVE-2022-27664<br \/>\nCVE-2022-30632 CVE-2022-30635 CVE-2022-32190<br \/>\nCVE-2022-34903 CVE-2022-37434 CVE-2022-40674<br \/>\n====================================================================<br \/>\n1. Summary:<\/p>\n<p style=\"text-align: left;\">OpenShift API for Data Protection (OADP) 1.1.1 is now available.<\/p>\n<p style=\"text-align: left;\">Red Hat Product Security has rated this update as having a security impact<br \/>\nof Moderate. A Common Vulnerability Scoring System (CVSS) base score, which<br \/>\ngives a detailed severity rating, is available for each vulnerability from<br \/>\nthe CVE link(s) in the References section.<\/p>\n<p style=\"text-align: left;\">2. Description:<\/p>\n<p style=\"text-align: left;\">OpenShift API for Data Protection (OADP) enables you to back up and restore<br \/>\napplication resources, persistent volume data, and internal container<br \/>\nimages to external backup storage. OADP enables both file system-based and<br \/>\nsnapshot-based backups for persistent volumes.<\/p>\n<p style=\"text-align: left;\">Security Fix(es) from Bugzilla:<\/p>\n<p style=\"text-align: left;\">* golang: crash in a golang.org\/x\/crypto\/ssh server (CVE-2022-27191)<\/p>\n<p style=\"text-align: left;\">* golang: net\/http: handle server errors after sending GOAWAY<br \/>\n(CVE-2022-27664)<\/p>\n<p style=\"text-align: left;\">* golang: path\/filepath: stack exhaustion in Glob (CVE-2022-30632)<\/p>\n<p style=\"text-align: left;\">* golang: encoding\/gob: stack exhaustion in Decoder.Decode (CVE-2022-30635)<\/p>\n<p style=\"text-align: left;\">* golang: net\/url: JoinPath does not strip relative path components in all<br \/>\ncircumstances (CVE-2022-32190)<\/p>\n<p style=\"text-align: left;\">For more details about the security issue(s), including the impact, a CVSS<br \/>\nscore, and other related information, refer to the CVE page(s) listed in<br \/>\nthe References section.<\/p>\n<p style=\"text-align: left;\">3. Solution:<\/p>\n<p style=\"text-align: left;\">For details on how to apply this update, refer to:<\/p>\n<p style=\"text-align: left;\">https:\/\/access.redhat.com\/articles\/11258<\/p>\n<p style=\"text-align: left;\">4. Bugs fixed (https:\/\/bugzilla.redhat.com\/):<\/p>\n<p style=\"text-align: left;\">2064702 &#8211; CVE-2022-27191 golang: crash in a golang.org\/x\/crypto\/ssh server<br \/>\n2107386 &#8211; CVE-2022-30632 golang: path\/filepath: stack exhaustion in Glob<br \/>\n2107388 &#8211; CVE-2022-30635 golang: encoding\/gob: stack exhaustion in Decoder.Decode<br \/>\n2124668 &#8211; CVE-2022-32190 golang: net\/url: JoinPath does not strip relative path components in all circumstances<br \/>\n2124669 &#8211; CVE-2022-27664 golang: net\/http: handle server errors after sending GOAWAY<\/p>\n<p style=\"text-align: left;\">5. JIRA issues fixed (https:\/\/issues.jboss.org\/):<\/p>\n<p style=\"text-align: left;\">OADP-1002 &#8211; DataMover: Backup partially fails for a namespace without PVC<br \/>\nOADP-1016 &#8211; DataMover: Restore randomly fails with &#8220;secrets vsr-lttsv-secret already exists&#8221; error<br \/>\nOADP-1020 &#8211; DataMover: restore partiallyFailed with &#8220;Plugin Panicked&#8221; error<br \/>\nOADP-1027 &#8211; DataMover: VSB fails with error &#8220;cannot obtain source volumesnapshot&#8221;<br \/>\nOADP-608 &#8211; Data mover restic secret does not support GCP<br \/>\nOADP-609 &#8211; Data mover VSR validation for default volumesnapshotclass and storageclass<br \/>\nOADP-611 &#8211; Data mover VSR resources are sometimes created multiple times with multiple PVCs<br \/>\nOADP-612 &#8211; Data mover Backup &amp; Restore needs to fail if a validation check fails<br \/>\nOADP-642 &#8211; OADP CRD descriptions should use the same capitalization as yaml fields<br \/>\nOADP-645 &#8211; Data mover performance on restore blocks restore process<br \/>\nOADP-662 &#8211; VSB\/VSR needs to fail if backup\/restore partially fails or fails<br \/>\nOADP-724 &#8211; Setting an excludedNamespace and includedNamespace in the same backup crashes velero<br \/>\nOADP-725 &#8211; DC Restic Post Restore Script handle restore name longer than 63 characters<br \/>\nOADP-731 &#8211; Backup partiallyFails with data mover if a stale snapshot is encountered<br \/>\nOADP-741 &#8211; Data Mover VSB\/VSR CRs do not include status on error<br \/>\nOADP-774 &#8211; OADP must-gather is getting stuck<br \/>\nOADP-794 &#8211; Second restore of CSI volume fails due to dataSource doesn&#8217;t match dataSourceRef<br \/>\nOADP-825 &#8211; CSI Volumesnapshot Deletion fails with nil pointer execption bug<br \/>\nOADP-849 &#8211; DataMover: restore PartiallyFails randomly with &#8220;ReplicationDestination.volsync.backube xxxx not found&#8221; error<br \/>\nOADP-927 &#8211; DataMover backup fails with nil pointer issue<\/p>\n<p style=\"text-align: left;\">6. References:<\/p>\n<p style=\"text-align: left;\">https:\/\/access.redhat.com\/security\/cve\/CVE-2020-35525<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-35527<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-2509<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-3515<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-27191<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-27664<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-30632<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-30635<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-32190<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-34903<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-37434<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-40674<br \/>\nhttps:\/\/access.redhat.com\/security\/updates\/classification\/#moderate<\/p>\n<p style=\"text-align: left;\">7. Contact:<\/p>\n<p style=\"text-align: left;\">The Red Hat security contact is &lt;secalert@redhat.com&gt;. More contact<br \/>\ndetails at https:\/\/access.redhat.com\/security\/team\/contact\/<\/p>\n<p style=\"text-align: left;\">Copyright 2022 Red Hat, Inc.<br \/>\n&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<br \/>\nVersion: GnuPG v1<\/p>\n<p style=\"text-align: left;\">iQIVAwUBY4RbZdzjgjWX9erEAQgR4g\/\/VRZ+qp8+3SHAQLZyC4J\/a+4XMiG1yNR9<br \/>\nARgZnotH77GFNptWir6E+3ojUutCuH1pULW5FSGoGEuctF7YyKuNl1MqQy6GMVAB<br \/>\ntRTdsqaHwyDDWeli\/hM1TtZoPnBpXd5H9eoT0gfVipIpoylYik2mXlLnmvItEmVB<br \/>\nFq0ECkcqT4aVw9pQxhdlfFf\/lwgbf9QNRKIil+A7sG7xgJQ5oAekB3tACRotKWkL<br \/>\nVDjg+yFOMnfDDI04dfXqdexa1qKS3NI4vopPPfSjK4P+UwneWmw\/VXykx0NNd2n9<br \/>\n490WMv49s2mNPRHGssZfRZd+Yw0knUb1Iglut0SsC3KLuQ1O+Hod8xCWL2a3N11d<br \/>\nPRybAWgKDy6WceiT\/VXUq7agbassWTAijt8QPkKrTEiJTnO7JdoSGNKzKEblp6dU<br \/>\ngauBKnVKmNlnFrAVuwxQ+pXu7arn70mq9wyjNbq1eC4v\/bpfXJsWYyCVmPpZ83wR<br \/>\nuFSz0IwxW6gePFsKtKJhtk8EP4jB3ATiNW53d7nV9Dz++X0ltioerowg\/sJGeFq7<br \/>\nuISozqrAeTXZXSrd5yL1Of6IDWD9Tb43GAh6GJE6JRNPmMv3yUcAppyv\/uHOyiKN<br \/>\nBEfOcFclp56QYWTBiYXWd5Gex5PQW3hdZpwUl3g8bDF+Ikrup7wI6ktw\/SejmZuc<br \/>\nuXOU76pYWW4=x6Pt<br \/>\n&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<br \/>\n&#8212;<br \/>\nRHSA-announce mailing list<br \/>\nRHSA-announce@redhat.com<br \/>\nhttps:\/\/listman.redhat.com\/mailman\/listinfo\/rhsa-announce<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211; Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: OpenShift API for Data Protection (OADP) 1.1.1 security and bug fix update Advisory ID: RHSA-2022:8634-01 Product: OpenShift API for Data Protection Advisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:8634 Issue date: 2022-11-28 CVE Names: CVE-2020-35525 CVE-2020-35527 CVE-2022-2509 CVE-2022-3515 CVE-2022-27191 CVE-2022-27664 CVE-2022-30632 CVE-2022-30635 CVE-2022-32190 CVE-2022-34903 CVE-2022-37434 CVE-2022-40674 ==================================================================== &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-34161","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34161","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=34161"}],"version-history":[{"count":1,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34161\/revisions"}],"predecessor-version":[{"id":34209,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34161\/revisions\/34209"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=34161"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=34161"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=34161"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}