RHSA-2025:0082HighCVSS 8.2

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.16.5 Bug Fix Update

Published
January 8, 2025
Last Modified
August 24, 2026

🔗 CVE IDs covered (10)

📋 Description

CVE-2023-26136 — tough-cookie: prototype pollution in cookie memstore CVE-2023-26364 — css-tools: Improper Input Validation causes Denial of Service via Regular Expression CVE-2024-21538 — cross-spawn: regular expression denial of service CVE-2024-24791 — net/http: Denial of service due to improper 100-continue handling in net/http CVE-2024-43796 — express: Improper Input Handling in Express Redirects CVE-2024-43799 — send: Code Execution Vulnerability in Send Library CVE-2024-43800 — serve-static: Improper Sanitization in serve-static CVE-2024-45296 — path-to-regexp: Backtracking regular expressions cause ReDoS CVE-2024-48910 — dompurify: DOMPurify vulnerable to tampering by prototype pollution CVE-2024-55565 — nanoid: nanoid mishandles non-integer values

🎯 Affected products99

  • RHODF 4.16 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:7ceb5166d9c43137bb81f019bd6b44b3bf9a51dc4d08cd28a5fd61ce7b1275e6_ppc64le as a component of RHODF 4.16 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:c8ebb628f7415530a9232ff7ff7de34e4195b5b5e3de88b86fcc3be9fa2506f0_amd64 as a component of RHODF 4.16 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:e13fe9d55b71b61daf4423492613cb9e071a2fb95139222a5bd9c48a66c2a3b8_s390x as a component of RHODF 4.16 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:801016723fe155f51b4bd560af9f959cfdbae156e836f70c38fc4ac128e84224_ppc64le as a component of RHODF 4.16 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:b81a39c6bf8cc96d20aa8faedb372b41da7add03e2106a3ed92e0c504e1bbb26_amd64 as a component of RHODF 4.16 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:e48d4ddfa672b0064ecad9879e6085033416efcc512926993aaf024b6744edfe_arm64 as a component of RHODF 4.16 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:ec1f6d95ec95311083a8e64f05296287a4e6f0f07859426e0e43715ee30b5716_s390x as a component of RHODF 4.16 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:8530893b46616b33bea1c50132c48ced28a9d2f1096685958055d874039aa6f6_amd64 as a component of RHODF 4.16 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:9947f2bbab306c1febe438ccd1df05137ae1e43f969460108c4bf2c8a9919a54_s390x as a component of RHODF 4.16 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:a0886744f3fb3f5943777d79da683db3b2b0ff0122856bb0b2eb907a5e4fb57f_ppc64le as a component of RHODF 4.16 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:2737626100f4945fff15ff5d0c996ea8f1e572bf54bd7822c3dd74a7314b8af8_arm64 as a component of RHODF 4.16 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:41dc86cf4206c1591829df4b58a18e5b88113ee37ced5d922175b6e3f78ba1ca_s390x as a component of RHODF 4.16 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:54edee74f13bc2e112eceb9ec3fb1bedc68fc403feb3c2e7134c268e9852573c_amd64 as a component of RHODF 4.16 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:b31bd2ab42dfb4e8526d28dd95052f3a5195db188aa28a68ef536d010a93dcf3_ppc64le as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-client-console-rhel9@sha256:2bf3f4edb13153991f1a6c13782c49b0885c4fc990891875de48f3d9214c3202_ppc64le as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-client-console-rhel9@sha256:c41c0adea953b393807cb096d2ab8d2a03c4e1edb8f1cb10128b4c800e26a0b7_s390x as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-client-console-rhel9@sha256:fd80d5abf223de2aa9b7133cc1470e439ebeb4b2f6bb2d01e41c0e8f6dacc408_amd64 as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:3bd68c9fd27ef33997e4436d90a7a6db93ecba305c234d3213a4c645c9f7942f_s390x as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:3cf0d4b0452c53d67552547631dacaac7200fde244540dd6c75dbd2d3b89e3e0_amd64 as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:a733de2812f7da8780cb69c2ea952da380e9511c7aac83c36c34039bb68e8d0e_ppc64le as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:4600f3f5ffe5d4e9dd6c1dba93568ae6b2ed79f995eca5facdf9e304b06055d6_s390x as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:4a6ddcce3b60bb13482c868a18f05219c7a061035e02148af77c959a12a69a9a_ppc64le as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:5acdb6ab66ec76754599e043609ed5e7f0fd843ddf53502a0ef195513a745961_arm64 as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:78e30cabc8defd83c519fc47e3ab9ebc26f31ca08712ddda05e404fc35cb26b2_amd64 as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-metrics-exporter-rhel9@sha256:135ca4673b18b8e4d331a9011e1f046b046b790b0df91bb6f04fde2422f2bb8a_s390x as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-metrics-exporter-rhel9@sha256:217506c01c3159c685e01965b0c36eb81d931fe5b02c80b99108c09df0fdd1b6_ppc64le as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-metrics-exporter-rhel9@sha256:5a6ce2c675ad3126970895abe6879a9417dea48b4cc0491e74bd0b1361322bf4_amd64 as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-operator-bundle@sha256:913814d92890e482e4b1fb177014bf8c51fc088390c6657de6ef97d6d3512531_amd64 as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-operator-bundle@sha256:94717251c9f063dfd16656a3fcf05c79dd4a7b48ea6a3e19650eedb61d10e216_ppc64le as a component of RHODF 4.16 for RHEL 9
  • +69 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: No mitigation is yet available for this vulnerability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (13)