- Issued:
- 2023-07-18
- Updated:
- 2023-07-18
RHSA-2023:4204 - Security Advisory
Synopsis
Moderate: VolSync 0.7.3 security fixes and enhancements
Type/Severity
Security Advisory: Moderate
Topic
VolSync v0.7.3 enhancements and security fixes
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE links in the References section.
Description
VolSync is a Kubernetes operator that enables asynchronous replication of
persistent volumes within a cluster, or across clusters. After deploying
the VolSync operator, it can create and maintain copies of your persistent
data.
For more information about VolSync, see:
or the VolSync open source community website at:
https://volsync.readthedocs.io/en/stable/.
This advisory contains enhancements and updates to the VolSync
container images.
Security fix(es):
- CVE-2023-3089 openshift: OCP & FIPS mode
Solution
For details on how to install VolSync, refer to:
Affected Products
- Red Hat Advanced Cluster Management for Kubernetes 2 for RHEL 8 x86_64
Fixes
- BZ - 2212085 - CVE-2023-3089 openshift: OCP & FIPS mode
- ACM-6336 - VolSync v0.7.3
aarch64
rhacm2/volsync-rhel8@sha256:b094c558db4d8a441a850601c13d76ffbfe0bb033cf38cd210e21ca6ffa2e52e |
ppc64le
rhacm2/volsync-rhel8@sha256:8c4f69f6bab3fd3d2c69f3961976df60bc2402ad4dda446bae5a0a86617e06c9 |
s390x
rhacm2/volsync-rhel8@sha256:63f39945356931a24c24bf94e2e0b3327d6467f87efced63625b1017090509da |
x86_64
rhacm2/volsync-operator-bundle@sha256:e317e898520ef06eb87cdb343634a45a4da8c15c241ce91cdecb0fb52303768a |
rhacm2/volsync-rhel8@sha256:80a6dcb18767844e1c65941aa4bc7805ef1ef888001e5256a1457d161567df31 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.