RHEA-2023:3686MediumCVSS 9.8

Red Hat Enhancement Advisory: OpenShift Virtualization 4.13.1 Images

Published
June 20, 2023
Last Modified
August 7, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2023-24538 — golang: html/template: backticks not treated as string delimiters

🎯 Affected products93

  • CNV 4.13 for RHEL 9
  • container-native-virtualization/bridge-marker-rhel9@sha256:275bcc6f653cd8ec28a7e87bac4812265a6aec448735e7ec8c676cd4566e4ca9_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/bridge-marker-rhel9@sha256:a6816c3de4b786f66fab69ae6325c851674b6755f85b5ab2a7bf816af5c963f0_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:69a5c410d9adba64bbd2e653322fa26fbd98e0ad2f8a3ba08d93317a27a08003_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:e85d9781fdeb2740c40d000994ada8049951974bae8729f9fd95c95083a650ff_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:9b7b8e24a568ccdbe2256167bc10e27799388781fa0d3e233beae92a251fbcec_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:ea76907afda91aa413ffc51490b3e61783d21032e38636f1ef94b5a8c8621ad7_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/cnv-must-gather-rhel9@sha256:2d23ec4b23f68e2a75bece1c7a6b79770e8c931e0a1ffa1649a9bd2f82aa9d08_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/cnv-must-gather-rhel9@sha256:49bc4b9e1736cc6ee5c076ab06438b7c564913336ca75be55fe8097338684789_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hco-bundle-registry-rhel9@sha256:cf696646c1b824969ce503d88ae2507062823f4466b9ce42c4f21ca7e7467d21_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hco-bundle-registry-rhel9@sha256:d5446d7245fefff9f24ee02ad3857f19bf363023eb4c78847de0f393cf3627f5_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hostpath-csi-driver-rhel9@sha256:6c16288df6e0209b66006076a5de515921092af090da609f6970b225fb6da138_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hostpath-csi-driver-rhel9@sha256:bc482c1428592524227ed5501a8a965bb752c8a902193aebdac41a6e9cd3b558_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:45678618a1b3b559cfe71c460a5370321bffeea9616562d93f87bb3c8d0873fe_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:587a1b75441e2ce4fbea21c81c825e1c5fbe6f2c8f637cc9d00b2b6aeea552d8_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hostpath-provisioner-rhel9@sha256:90ef66f42f4f0dcd2af6f04a03b7fcfe5833532fa7cbd4c823f00ae4d2c44a96_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hostpath-provisioner-rhel9@sha256:ab6962c133395bd668202988e39365557adcb692933b43152640f8378ffdfa11_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:712b2d7d1c53fe111b92bd04f52fdcbf1e56f7da40d72dc06b051b21ca11e407_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:8e81e65b9f8b83944d3d11adcd1a268586b9fa57b8c30b6e82e9d890549bc4b5_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:5f602d808b045e36b6a9c2708a8d0cf17ec6cda856fd69c0315114b62184c999_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:ba28f534ff8e266004dca1aff9821547e642ab536d44730edc8acc0ac2b3fcba_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/kubemacpool-rhel9@sha256:4475bc742ca15b30ceaa6b1726bc40fdd09f11e7eceb2d91dec660064751078c_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/kubemacpool-rhel9@sha256:e51028d71cf9bd2aba681976393095534e7c0ed46c7b11c152d66d7588ed3c60_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/kubesecondarydns-rhel9@sha256:29d4f668b1a4200d2b41e6ea1427aa742fca2e96d121867e81155b09d2a06384_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/kubesecondarydns-rhel9@sha256:af6089e378df9af866756a296d98f71d9a5ddb9e01b4ccdfb892e035565b33a5_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:07094bc158d4a02d8cfd250d9cf44676e495dfb3c6c0a6fe83643126351bbf2c_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:8129f1502f61bbb43aa94eb01db9002f05387ddae8fea568ee97dc4c5fd6be55_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/kubevirt-dpdk-checkup-rhel9@sha256:6d838dc84bcfdf4af5e2745800a099555de0531d610e571b3d1ae8b5624de238_arm64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/kubevirt-dpdk-checkup-rhel9@sha256:b76efd06f5076fdb02c3c8a560be2a2dc6413b6220b1be928b958a7fedccf8a1_amd64 as a component of CNV 4.13 for RHEL 9
  • container-native-virtualization/kubevirt-ssp-operator-rhel9@sha256:419763ecf178be0ea16127e4f9bf3f01a827bb176d27aadf594c717eb9d1323c_arm64 as a component of CNV 4.13 for RHEL 9
  • +63 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (20)