RHSA-2025:0079HighCVSS 8.2

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.17.2 Bug Fix Update

Published
January 8, 2025
Last Modified
August 24, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2024-21538 — cross-spawn: regular expression denial of service CVE-2024-43796 — express: Improper Input Handling in Express Redirects CVE-2024-43799 — send: Code Execution Vulnerability in Send Library CVE-2024-43800 — serve-static: Improper Sanitization in serve-static CVE-2024-48910 — dompurify: DOMPurify vulnerable to tampering by prototype pollution CVE-2024-55565 — nanoid: nanoid mishandles non-integer values

🎯 Affected products106

  • RHODF 4.17 for RHEL 9
  • odf4/cephcsi-operator-bundle@sha256:84ee4e907361648d1249c9333e7af761708e5ce3a244f8963d71bd6f76a70439_s390x as a component of RHODF 4.17 for RHEL 9
  • odf4/cephcsi-operator-bundle@sha256:cc7efc137a03e402c8ce570818ff5d285bd9d7a3b7e198d8b7757b9a3e5908a1_amd64 as a component of RHODF 4.17 for RHEL 9
  • odf4/cephcsi-operator-bundle@sha256:fc991288aef78334dc19380cc5f80492bb25bee7c8fda79e552c384db064b220_ppc64le as a component of RHODF 4.17 for RHEL 9
  • odf4/cephcsi-rhel9-operator@sha256:2a35f5ba5c9ad6106bae6988671f0025d4450868ae705714b791be081ecc5495_arm64 as a component of RHODF 4.17 for RHEL 9
  • odf4/cephcsi-rhel9-operator@sha256:54f6bf8b64afc3d4dd2e6ea12e72ce06cbab86ec507c1252cc34585cf3ee3fcb_amd64 as a component of RHODF 4.17 for RHEL 9
  • odf4/cephcsi-rhel9-operator@sha256:bffa592135687eef55d95e8b88beb6deda2015e8da86f03c471dfdbb105fca40_ppc64le as a component of RHODF 4.17 for RHEL 9
  • odf4/cephcsi-rhel9-operator@sha256:e0182b77bb51605b9cd77322ad8a61bb9cf74eb84d5ceef512330b7138396fee_s390x as a component of RHODF 4.17 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:5ed6e1b53d317f77a578a6e8786d2eab02d47995ccc093df4a11316ed47e6c87_s390x as a component of RHODF 4.17 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:8f32d658563f095fe196f4e23be66f5f5afd48a97bf929c35bc11eb0db1d5226_ppc64le as a component of RHODF 4.17 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:d54fd1a2345699a240a7d65d09ac7eb6da8df7d582fe0bbef309c206427d4958_amd64 as a component of RHODF 4.17 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:162aeae7c3910ed7404e0ef7d881188a5e5f58f2f2a2debe22bb16f9638eb0aa_amd64 as a component of RHODF 4.17 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:4ac2448215ef79cbfaa2be5d2d15552e7545f686e08f221f734fae87ed2d719b_arm64 as a component of RHODF 4.17 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:8edd7771c1c6685766bce549ba9b43d851935e7241b3b0ada27f85943b6b7cc0_ppc64le as a component of RHODF 4.17 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:ac79fb6e7346571cd547f28a06b3f9160ebfa2167df8ae4666bee118fe23c9f7_s390x as a component of RHODF 4.17 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:268e42ceb31e7d3e404fe1789e00456a23d47aff83fdc8a6e2f33b611f74a1d3_ppc64le as a component of RHODF 4.17 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:3876b8d184301508d72ea48ca5d3b764776b3de8791a241478f5eff9d6b81b06_s390x as a component of RHODF 4.17 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:4fed3aaad75c98bd90cdbd81c67d590ee86dadf64aea6e93d0a1e48e6ef273c7_amd64 as a component of RHODF 4.17 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:1f07db58c965bd7c5e817d6585318934a34ea8ab7f880faac0ba27e2aed5d6c8_s390x as a component of RHODF 4.17 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:50e47948901795bd0e3bc7a828266a1b4d0e958fdfaf8dcfd85f805853f63e41_amd64 as a component of RHODF 4.17 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:57ca5c5a78fb55760a0ff22ffcaae42bfd185ff73536a710e6297b5cbf8de6b3_ppc64le as a component of RHODF 4.17 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:944698a0fc7e6486d8f5852e41d192f4b2a82d0b26dde20727369cf996cdcb28_arm64 as a component of RHODF 4.17 for RHEL 9
  • odf4/ocs-client-console-rhel9@sha256:79b15f4f324f4a1013a6b0099e166313c1aef9d6d63bb5ef76969d59b8c92782_ppc64le as a component of RHODF 4.17 for RHEL 9
  • odf4/ocs-client-console-rhel9@sha256:83b57f2c76262e933fb1c80acb6a9d6b4c12e300171335c92f676ee47972490e_s390x as a component of RHODF 4.17 for RHEL 9
  • odf4/ocs-client-console-rhel9@sha256:be15a41d01476fac0800d17a923debc8195a9b5149436c7ed6aa28547a699604_amd64 as a component of RHODF 4.17 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:31a9db5567859cd5c57a7e327f6027da90a8b6c2f517be1c69e5bcce7b2815df_s390x as a component of RHODF 4.17 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:78386fb2e4d17772ca03331f85bc9ee13b9b60721dfcb62e75cad59f2845991a_ppc64le as a component of RHODF 4.17 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:b95a20c8dfc09cb0ed7f2a3639f279bd09d7f306a28730e092e899adfb62e36a_amd64 as a component of RHODF 4.17 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:6d43d5dd3ba338fed7829368e5954bbac0525d5b4d30bb2ff7e38114c0933fa5_arm64 as a component of RHODF 4.17 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:7330de229659f3f60022f24c6f2eaf519bd94a6ba1c943cc10b5225525c16fc4_amd64 as a component of RHODF 4.17 for RHEL 9
  • +76 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (9)