RHSA-2024:6122HighCVSS 9.9

Red Hat Security Advisory: OpenShift Container Platform 4.18.1 bug fix and security update

Published
February 25, 2025
Last Modified
August 22, 2026

🔗 CVE IDs covered (25)

📋 Description

CVE-2023-44270 — PostCSS: Improper input validation in PostCSS CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2024-3727 — containers/image: digest type does not guarantee valid type CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file CVE-2024-6508 — openshift-console: OAuth2 insufficient state parameter entropy CVE-2024-7387 — openshift/builder: Path traversal allows command injection in privileged BuildContainer using docker build strategy CVE-2024-9341 — Podman: Buildah: cri-o: FIPS Crypto-Policy Directory Mounting Issue in containers/common Go Library CVE-2024-10963 — pam: Improper Hostname Interpretation in pam_access Leads to Access Control Bypass CVE-2024-12085 — rsync: Info Leak via Uninitialized Stack Contents CVE-2024-12698 — ose-olm-catalogd-container: incomplete fix for rapid reset (CVE-2023-39325/CVE-2023-44487) CVE-2024-21538 — cross-spawn: regular expression denial of service CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-39338 — axios: axios: Server-Side Request Forgery CVE-2024-43803 — Bare Metal Operator: BMO can expose particularly named secrets from other namespaces via BMH CRD CVE-2024-45296 — path-to-regexp: Backtracking regular expressions cause ReDoS CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2024-45496 — openshift-controller-manager: Elevated Build Pods Can Lead to Node Compromise in OpenShift CVE-2024-47211 — openstack-ironic: Lack of checksum validation on images CVE-2024-48910 — dompurify: DOMPurify vulnerable to tampering by prototype pollution CVE-2024-50311 — GraphQL: Denial of Service (DoS) vulnerability via GraphQL Batching CVE-2024-50312 — GraphQL: Information Disclosure via GraphQL Introspection in OpenShift CVE-2024-52798 — path-to-regexp: path-to-regexp Unpatched path-to-regexp ReDoS in 0.1.x CVE-2024-53104 — kernel: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format CVE-2025-21613 — go-git: argument injection via the URL field CVE-2025-21614 — go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.18
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:a8732a7ca709d9fd409f36af7cccf5a4ab809cc64b1b2ce303a1088f5500b6d7_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:ae06a68b9fada2d627a22ea047070cd5d695203ad3345efd82a8749f2960f557_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:c1e9d8836d34c95c9c013915221049ccf7a8d7c7d210b40d84f6899769bc3db4_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:c2059aca8304609132f0d217e47a3feb0a188f01dbdc6a86d0dbf35eb9721ae6_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:0a0dcb87609718ceb5e0ddfbe0ee6ada3c9f495c4b45b2453000351aff3c5f47_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:0eec9c0651b0caa0af7d8ef36616acfce227e0528f0626eee172e89516c69fc2_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:288e46a2b17e5ba161c40d17dbda984ca16cee861168a06766ef4575864d6783_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:9f425681af97666a14afc187b72c4208cbca05f6d8eab50042a97c180b96a9b8_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/azure-service-rhel9-operator@sha256:2658d64017fb43f5e805e912ba69051f2661769465216ae5a0154efef8555b7b_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/azure-service-rhel9-operator@sha256:2841e88142d3ddd1453acec692e3fe1633db82bf9f6f4820d63215f2355a5520_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/azure-service-rhel9-operator@sha256:43d2996fdc94a1f39c17705b41f5e37ccb4a8207dd0ff672d8f71029a3c4f2d4_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/azure-service-rhel9-operator@sha256:631be62a8786b9af9c585a25c3ad1d6ef3ee3e53e5bed1798db4251a48bc8f5a_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/cloud-network-config-controller-rhel9@sha256:463024ea9179879340c44b21bc2e383927270f33dbd0cf69727387a607cab544_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/cloud-network-config-controller-rhel9@sha256:8048f1cb0be521f09749c0a489503cd56d85b68c6ca93380e082cfd693cd97a8_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/cloud-network-config-controller-rhel9@sha256:b27ad99dfcc42eeabf477d14e18fb5993ff346789bf387f49cc6a014cb74c386_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/cloud-network-config-controller-rhel9@sha256:b305d789373c4bb61fbbbc86d63970e1ab9ac4ce9d8a30c8e92a253664cdc46f_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:292e79571179629e3d2435d6b9d3caf1d8727c500a2e2af8d941cefe4112ba0d_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:93031f2be17137041fec30d8d4781bb54e25e7ecbf0d12783c23de810ec33967_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:9b89cd7df668045a9fd2b158fe4c3eedc83e3259e6db78c978928c5b1fed3a8d_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:be0c648df082d0124b73944625c96dfc17b7cdb7a84ad7acea49e85eb6c2a8b2_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/driver-toolkit-rhel9@sha256:1e4bd66208652f8eb6395cbcc3c0c37897368ae051479dd04e6b87d19a3b7bb9_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/driver-toolkit-rhel9@sha256:86ea34129b0827fa58341da2f8d44dea5e89d3589e4c08c5e63111cc7ae65ddb_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/driver-toolkit-rhel9@sha256:c9784e3ebb982191eff2b28e61eb3b935d73f92672aa82bb48e0fd9424356f91_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/driver-toolkit-rhel9@sha256:f336eb9a9efcd0a3a523104da0b3f6191096db812b3c6fae178607a9e4ce7435_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/egress-router-cni-rhel9@sha256:3e9653bc7cf3607a8f1731ebb61cbdf3ef960516e4c4c054ea4bfb3a623a9398_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/egress-router-cni-rhel9@sha256:b911e5404e21a9f32ea5a7e3b43f9cf8c2705e376af8c798aa38308c58da541e_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/egress-router-cni-rhel9@sha256:b9e3232996902d1f35be0faac3f542a2ac475722a73436f6b38df3e4fd8934e8_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/egress-router-cni-rhel9@sha256:e40792096b162f0f9ce5f8362f51e5f8dea2c1ce4b1447235388416b5db7708c_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • openshift4/frr-rhel9@sha256:5dbf844e49bb46b78586930149e5e5f5dc121014c8afd10fe36f3651967cc256_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.18/release_notes/ocp-4-18-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:d9c985464c0315160971b3e79f5fbec628d403a572f7a6d893c04627c066c0bb (For s390x architecture) The image digest is sha256:bd033a80f4586380ee46ac0ab9147e2157942e1f41ec92fdb6d3d32f839afcbd (For ppc64le architecture) The image digest is sha256:4a690927d43044e2b42d6e64b04be8dcf164b2b95d0fde03163b88852ff0188d (For aarch64 architecture) The image digest is sha256:d285ba31afa245c14f9354626b44abf833fe600774c1fd110ea5e712531bf914 All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.18/updating/updating_a_cluster/updating-cluster-cli.htmla Workaround: There's no known mitigation for this issue. Red Hat recommends to not parse untrusted CSS input using PostCSS. Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Cluster admins can follow the instructions in "Securing Builds by Strategy" to block use of the "Docker" build strategy on a cluster, or restrict the use to a set of highly trusted users, until the cluster is able to be upgraded. https://docs.openshift.com/container-platform/4.16/cicd/builds/securing-builds-by-strategy.html Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To reduce the risk, administrators should ensure that no DNS hostname matches local TTY or service names used in pam_access. Additionally, implement DNSSEC to prevent spoofing of DNS responses. For stronger protection, consider reconfiguring pam_access to only accept fully qualified domain names (FQDNs) in access.conf Workaround: Seeing as this vulnerability relies on information leakage coming from the presence of data in the uninitialized memory of the `sum2` buffer, a potential mitigation involves compiling rsync with the `-ftrivial-auto-var-init=zero` option set. This mitigates the issue because it initializes the `sum2` variable's memory with zeroes to prevent uninitialized memory disclosure. Workaround: Red Hat Product Security does not have any mitigation recommendations at this time. Please update as soon as possible. Workaround: The Operator can configure BMO RBAC to be the namespace scoped for Secrets, instead of the cluster scoped to prevent BMO from accessing Secrets from other namespaces. Workaround: Cluster admins can follow the instructions in "Securing Builds by Strategy" to block use of the "Docker" and “Source” build strategies on a cluster, or restrict the use to a set of highly trusted users, until the cluster is able to be upgraded. https://docs.openshift.com/container-platform/4.16/cicd/builds/securing-builds-by-strategy.html Workaround: GraphQL Introspection should be disabled. Users should not have the ability to view all available queries, mutations, and data types. Workaround: Avoid using two parameters within a single path segment when the separator is not, for example, /:a-:b. Alternatively, you can define the regex used for both parameters and ensure they do not overlap to allow backtracking. Workaround: This flaw can be mitigated by preventing the `uvcvideo` module from loading. See "How do I prevent a kernel module from loading automatically?"[1] for more information. Note that disabling this module will prevent UVC devices such as webcams or video capture devices from functioning properly. Preventing the `uvcvideo` module from loading is also an effective mitigation for OpenShift environments. Different methods of applying that mitigation are available, depending on the vulnerable cluster's configuration. See "USB CVE-2024-53104 Mitigation for OpenShift" [2] for more details. That document also details alternative mitigations available through the use of compliance profiles and USBGuard. 1: https://access.redhat.com/solutions/41278 2: https://access.redhat.com/articles/7107058 Workaround: In cases where it is not possible to update to the latest version of go-git, it is recommended to enforce validation rules for values passed in the URL field.

🔗 References (1068)