RHSA-2025:0164MediumCVSS 6.5

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.15.9 Bug Fix Update

Published
January 9, 2025
Last Modified
August 24, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2023-26136 — tough-cookie: prototype pollution in cookie memstore CVE-2023-26364 — css-tools: Improper Input Validation causes Denial of Service via Regular Expression CVE-2024-21538 — cross-spawn: regular expression denial of service CVE-2024-43796 — express: Improper Input Handling in Express Redirects CVE-2024-43799 — send: Code Execution Vulnerability in Send Library CVE-2024-43800 — serve-static: Improper Sanitization in serve-static CVE-2024-45296 — path-to-regexp: Backtracking regular expressions cause ReDoS

🎯 Affected products90

  • RHODF 4.15 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:09e31fd9fcf5384bf4b38a9ebf9a2d61743b9e127a4f054b9f623e69f27f86ac_amd64 as a component of RHODF 4.15 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:3937c42c64a9081ddc0a4b5525becdd2447aae95ae5185b59763f5cd6d8d9ed5_ppc64le as a component of RHODF 4.15 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:b7b3409ff5f52b3fa2c7f84f996f7468686e0a900b77e857ef9a4495e8556c68_s390x as a component of RHODF 4.15 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:51e0b564b23b53da2ddf70a672c039afb38e19447c7ecdbe98984bdb081465db_s390x as a component of RHODF 4.15 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:7817a2d1b6de114ca1b5226d09be4094eaa835b9c7d0a41086805cb4163ac443_arm64 as a component of RHODF 4.15 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:9094e2fd73c5f596670851b5e34682b944df891a02dac93286f3b773caf4af31_ppc64le as a component of RHODF 4.15 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:ca9bfe19cc69400e2bd4700f29017fe9ec87f057e61babf38fc239b50cff3de8_amd64 as a component of RHODF 4.15 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:bcd9e01713211bfebd7447161aa5c74a76e05247dd545f32855ed962fb0d6823_s390x as a component of RHODF 4.15 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:d62e96c9eb95d55df1cee4aed2b5dc3e91bde16f4a70b2a796841040813a36b7_amd64 as a component of RHODF 4.15 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:e64903ef260263c7f0779b8c9797725c423ce752cdb89935c43d35b184c7e45d_ppc64le as a component of RHODF 4.15 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:0ed292c91ef8252f3f77454c1a5bdc8c5537514ec0fe11e352cdb4f6b2649395_amd64 as a component of RHODF 4.15 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:4c83b9041674c6e1e4a84afbdc8c7a81f73de21e82f20dc1c6afb771847d5b49_ppc64le as a component of RHODF 4.15 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:66b735da50b05a5a22cbf53b663509d308017a217fea035fa70b09fecefe86c4_arm64 as a component of RHODF 4.15 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:6fd9acdf1a8521a400640236fdcaecab834ad065cdf64f1004094315ccf8f2e9_s390x as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-client-console-rhel9@sha256:65fbf4dbc21b4aae396354468c0e8a745050e2336b5761b9bc653fa95379dd7f_ppc64le as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-client-console-rhel9@sha256:b30986a29f5baf8c017fc7afa9d652711c23220094d556d43e01a817fe4daf1d_s390x as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-client-console-rhel9@sha256:e69658ef8a9410a42d877e8d32e300b83190e8ad3d4135bcfbca40ea048b9b13_amd64 as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:384b4b031d0851fcee92ab683166c76e1e4189cc01c84d10bc03e50b22d884a6_ppc64le as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:48b734787a14525410dc36bfb96a8b270fabef6e28cb36bc018c673cf10ebe6e_amd64 as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:f80cf655d891a16f218dbae983ecc0d7198912a27f2756cafa9b868a7b00da7c_s390x as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:1cb2a857941d2f629b1da758afcc4f6f05e16ae00eb6b3f35fdb58893f16420a_s390x as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:44e3d98c19e610e9fa811f41891aaae979467cfa91c2857e213583e4bc59e1a7_arm64 as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:c455b1a39487855d949c4fa3902fa295fcaeda7c491c40d184b05ab574b94308_amd64 as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:ec22e19a1a0c9dfb748f92836cdbe962d5d0a2357f6d886bf42e0e42c59dceb4_ppc64le as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-metrics-exporter-rhel9@sha256:3157bbe3ec0600100311d7ed133847c62cee5262ca882001857d9d6d5c26d6e4_ppc64le as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-metrics-exporter-rhel9@sha256:578e0e4e00460806914d4d00226401465265eb1dd43a2401f2ff988e1c83806a_s390x as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-metrics-exporter-rhel9@sha256:5f1f93569937823dcdca79af386c09940568667800eee988c874ae9fbd6ec792_amd64 as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-operator-bundle@sha256:114edc4bebdc0cad21feec6f94f60d61f2497929f905474204f5c9aa8191e713_ppc64le as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-operator-bundle@sha256:600c7c62bc8b670abed7669204eb8ba0ea5381b50f55c3155328704f57e6fac9_amd64 as a component of RHODF 4.15 for RHEL 9
  • +60 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: No mitigation is yet available for this vulnerability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (11)