Lucene search

K
redhatRedHatRHSA-2023:4575
HistoryAug 08, 2023 - 5:14 p.m.

(RHSA-2023:4575) Moderate: VolSync 0.5.4 security fixes and enhancements

2023-08-0817:14:50
access.redhat.com
34
kubernetes operator
asynchronous replication
persistent volumes
clusters
container images
security fixes
ocp
fips mode
unix

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.058

Percentile

93.5%

VolSync is a Kubernetes operator that enables asynchronous replication of persistent volumes within a cluster, or across clusters. After deploying the VolSync operator, it can create and maintain copies of your persistent data.

For more information about VolSync, see:

https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.6/html/add-ons/add-ons-overview#volsync

or the VolSync open source community website at: https://volsync.readthedocs.io/en/stable/.

This advisory contains enhancements and updates to the VolSync container images.

Security fix(es):

  • CVE-2023-3089 openshift: OCP & FIPS mode

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.058

Percentile

93.5%