RHSA-2023:5376HighCVSS 8.1

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.13.3 security and bug fix update

Published
September 27, 2023
Last Modified
August 4, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2023-24540 — golang: html/template: improper handling of JavaScript whitespace CVE-2023-26115 — word-wrap: ReDoS

🎯 Affected products84

  • RHODF 4.13 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:232c3178bed85fb7de98a1740b79c076a43361a95adec6ad46a2bc78d26cd806_amd64 as a component of RHODF 4.13 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:81a8210bc44d930097da17bc390b5f215f74e1a9448744ab968192aa0160563c_ppc64le as a component of RHODF 4.13 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:b1c8b5dba7b83cca14daaa0255ad7a90912de0e0da8367054be031063f3c7278_s390x as a component of RHODF 4.13 for RHEL 9
  • odf4/mcg-cli-rhel9@sha256:4678fc61d47f98c000efdffe5bfb3da760ba8c0ba1f7b5c8e525b0618d68ab21_s390x as a component of RHODF 4.13 for RHEL 9
  • odf4/mcg-cli-rhel9@sha256:59a966151fbb1b1dba8ed8a59818401fb606b7e0823f9b97c9d4c7646dd6b9b1_amd64 as a component of RHODF 4.13 for RHEL 9
  • odf4/mcg-cli-rhel9@sha256:9226a0bff43abb19535fb87f4dc33087569b4f096da39e39f56392c5d8e1aa18_arm64 as a component of RHODF 4.13 for RHEL 9
  • odf4/mcg-cli-rhel9@sha256:e74a1ffb4423c26f2aa634b86a9042c07f9f230a569dee5a832e64299abac4d6_ppc64le as a component of RHODF 4.13 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:76a3ed8fba4ca51e7d01d5e392be6b213cbc2ba86cef3a38376f7f2a61289d0b_s390x as a component of RHODF 4.13 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:a12f8054a2ca69c979abac544a6c3a934442898f11900abc4430d47d4db853b1_amd64 as a component of RHODF 4.13 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:c48de169132b4c10f443b7602078d5d494269e2fb70449352469595e631dfdc5_ppc64le as a component of RHODF 4.13 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:d8894fa3ab4f106feb3b0abb19e36b1725663ba70bdeae7d33a32279f2353034_arm64 as a component of RHODF 4.13 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:1217b18f51480accd2d5eeb949699c89065a3b38f12e3bfbda60660a57dfdca9_ppc64le as a component of RHODF 4.13 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:30828cb79cac11ba206a4528e846ff660635f4bf48207af287bd94aad6d6d67a_s390x as a component of RHODF 4.13 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:ebf4cd9bc3076bf9286977b29a943773fa8c249afdc2bfa1b911a2c0f0e5ccf7_amd64 as a component of RHODF 4.13 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:044b19ac05dfffc305f32f58376cd6eca1f0fa67462e093940f7d3bc60cb8a1e_amd64 as a component of RHODF 4.13 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:55c050267dc55c6c9904a64cf59b63048839bbdd0cefd5ca25e8abbb4efe7273_arm64 as a component of RHODF 4.13 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:5bafd25be7f2d979be4caddc8e108af674f0d8fa5ae04410439e0bc673bd8fd4_s390x as a component of RHODF 4.13 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:676dd3170980201e08f6db25236c32d508653fe97bee87bb5cc3e0358cc852a4_ppc64le as a component of RHODF 4.13 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:13b7e4961d0aa84c2bbe2866a6291d5fbd0934faf8852297a07c571bce28e95b_s390x as a component of RHODF 4.13 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:1bafb2182f6bac9ad052a9dff0eb5ee15f9a85c0bc9f0c9dd4d1182e221df0ec_ppc64le as a component of RHODF 4.13 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:7da60a69b11eb39114afb0b7ce966a084e4c1c351fc01fe6022148fcf860d2b0_amd64 as a component of RHODF 4.13 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:39042f82fba928abbf923ff78204b4977e0817fd452359b635f20ecaceda3e52_arm64 as a component of RHODF 4.13 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:77de2c61dc21d35413ba5bd6038bff5ecd4ff17a31b2163959a6d296bf848f26_amd64 as a component of RHODF 4.13 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:b912621367fc394a2a94ce0c330bf9f7cbc31c60749dbb2932a49fcd4cf76d4a_s390x as a component of RHODF 4.13 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:cb99ab65b33c8b72bbb26233f6b123010ca4c5fbe7cdff611f29bc465d565c73_ppc64le as a component of RHODF 4.13 for RHEL 9
  • odf4/ocs-metrics-exporter-rhel9@sha256:691d9eab91e79a2222bca3a27f6bbd33c6fc0f7d67771ce0f72fb5d2faa4d4fb_s390x as a component of RHODF 4.13 for RHEL 9
  • odf4/ocs-metrics-exporter-rhel9@sha256:7128c230c0c75ef86a97cb83d72ec64c61b67897bc6a93f3b673fd50f6558d1b_amd64 as a component of RHODF 4.13 for RHEL 9
  • odf4/ocs-metrics-exporter-rhel9@sha256:7d83e7a6925670deac20d6f35e01bc26b7c29aa8c77dc6065958aa95c74723ac_ppc64le as a component of RHODF 4.13 for RHEL 9
  • odf4/ocs-operator-bundle@sha256:393c702609ca9aa209fc65d280895b5f483923a3b2378d9fc6661ca89e93afa9_amd64 as a component of RHODF 4.13 for RHEL 9
  • +54 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (15)