RHSA-2024:6121HighCVSS 8.2

Red Hat Security Advisory: OpenShift Container Platform 4.18.1 security and extras update

Published
February 25, 2025
Last Modified
August 22, 2026

🔗 CVE IDs covered (13)

📋 Description

CVE-2019-25210 — helm: shows secrets with --dry-run option in clear text CVE-2023-44270 — PostCSS: Improper input validation in PostCSS CVE-2024-21538 — cross-spawn: regular expression denial of service CVE-2024-45337 — golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2024-45590 — body-parser: Denial of Service Vulnerability in body-parser CVE-2024-48910 — dompurify: DOMPurify vulnerable to tampering by prototype pollution CVE-2024-52798 — path-to-regexp: path-to-regexp Unpatched path-to-regexp ReDoS in 0.1.x CVE-2024-55565 — nanoid: nanoid mishandles non-integer values CVE-2024-56201 — jinja2: Jinja has a sandbox breakout through malicious filenames CVE-2024-56326 — jinja2: Jinja has a sandbox breakout through indirect reference to format method CVE-2025-21613 — go-git: argument injection via the URL field CVE-2025-21614 — go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies

🎯 Affected products192

  • Red Hat OpenShift Container Platform 4.18
  • openshift4/ingress-node-firewall-rhel9-operator@sha256:0ea4bb9eec41ad07335136f14b8d3d90ccefe92455ba700b118c8c607aac0310_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ingress-node-firewall-rhel9-operator@sha256:692b86338db5d73bd1eae62821bf87f1509a6980c4f4dc920d709ebba16f648f_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ingress-node-firewall-rhel9-operator@sha256:c5e18615b877b8dfe03496471111cf0b697bab1f683190013c5e03482b2e5c2c_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ingress-node-firewall-rhel9-operator@sha256:c9d4fbb096a01cf0ec62f6e4afe285505edc049a5cb734b5cbe20b255cd95a8b_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ingress-node-firewall-rhel9@sha256:50db8deca9fe2af0dd52944f7647542002091d62cd7a7b2ea940c91f18d38f62_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ingress-node-firewall-rhel9@sha256:776abf470481abaf65891989a555e43c746cfe748dfab74ffc6faec1e943e5e6_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ingress-node-firewall-rhel9@sha256:e7337f3cfacb16e39767737f0ce0d62145db87f0b6306c8a439c01849d3db3d5_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ingress-node-firewall-rhel9@sha256:ea0940c5e21ed660e36e2ee299932ce099916dd44cd4b570d7efd64efda8d03e_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/kube-compare-artifacts-rhel9@sha256:5d6b54d3dff82b0373406ca89607754ade8049459b6edd9ba7236ccdf6106652_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/kube-compare-artifacts-rhel9@sha256:674835839de3a2fe38d38fb819eb9cd0f2bcdfe9d975803b93e49185344da69f_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/kube-compare-artifacts-rhel9@sha256:9db6fea83d9b811dfcc747f4ef13dc7d06eaf09b1d386338dd1bf626a2726769_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/kube-compare-artifacts-rhel9@sha256:d0c1613fc6a207f12b4016906245747e0fe118dbad8ed82c8ef83194b597ce8d_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:51aeb6523b429cb3fac82715a2069fba1a05adae06b01173974e916cd4116c1d_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:a83f242195b11d38d93643383e0bef8b2c673ed65be2f37ffd8f792fa710b632_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:c4765e5ee700a51f4a46e5db95ee773dc59389e133c0f79322e2610b5db32655_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:eee2d0c8474b187f1ccdd605506faec3da24e8939f210a73efc372564b46ede7_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/metallb-rhel9-operator@sha256:133312ed995542d0f3155f58334392610cf8f9330dd18c35991778a54ff6877e_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/metallb-rhel9-operator@sha256:154668eab8d594f164de6f7268643a3637eaeb41ab7ddd99198a5d3a16c36ff0_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/metallb-rhel9-operator@sha256:35a34735f5df6a96514e93da27f09f50f3814690ab1f504756151c3c2eaec0e1_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/metallb-rhel9-operator@sha256:f6176a06e8c87dba27c71e80d7f95f7ae319f764e51e227a1e1597a22cea5780_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/metallb-rhel9@sha256:120caae223b222d1541d7413749e126fe61fffe7bfd156df462953bf3d230398_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/metallb-rhel9@sha256:1686ec0d80bc5e655b561a2f4511504b922a447abd8aeeb15dafca8293ef5aaa_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/metallb-rhel9@sha256:8bc52c37cf3890ae26cf987b269e2291824a401c316e1c899eb42c204ce57a1a_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/metallb-rhel9@sha256:d526941a3579d6af7eff53cdbdbf5c095df3de781ad8203a9676a2f52fd25d5b_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/nmstate-console-plugin-rhel9@sha256:07c944ce0713b5c9632660e3fe1394312acc14b430a96dd895cdfef70e5a4a70_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/nmstate-console-plugin-rhel9@sha256:4fc4d31775b85b3106818a1a8b0a6582592a3fcba07ae339dbb132d33dc19029_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/nmstate-console-plugin-rhel9@sha256:f2af50d5c7aed22b146d51ec1df352ff19bd61d4138b2a2db73ceeb9ab58742f_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/nmstate-console-plugin-rhel9@sha256:fc6d1ce22cb8bcb3dd97ee72c1d12255031b031f5f69622aee45c44c4e7f946e_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/ose-ansible-rhel9-operator@sha256:03f83bb85eb9016a713127d2760044f988fe517cf7541dd75585963b853afc85_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • +162 more not shown

✅ Remediation

For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.18/release_notes/ocp-4-18-release-notes.html Workaround: There's no known mitigation for this issue. Red Hat recommends to not parse untrusted CSS input using PostCSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Avoid using two parameters within a single path segment when the separator is not, for example, /:a-:b. Alternatively, you can define the regex used for both parameters and ensure they do not overlap to allow backtracking. Workaround: To mitigate this vulnerabilty restrict user-controlled template filenames, ensuring they follow a predefined templates. Workaround: In cases where it is not possible to update to the latest version of go-git, it is recommended to enforce validation rules for values passed in the URL field.

🔗 References (39)