RHSA-2025:0323MediumCVSS 6.5

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.14.13 Bug Fix Update

Published
January 15, 2025
Last Modified
August 24, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2023-26136 — tough-cookie: prototype pollution in cookie memstore CVE-2023-26364 — css-tools: Improper Input Validation causes Denial of Service via Regular Expression CVE-2024-43788 — webpack: DOM Clobbering vulnerability in AutoPublicPathRuntimeModule CVE-2024-43796 — express: Improper Input Handling in Express Redirects CVE-2024-43799 — send: Code Execution Vulnerability in Send Library CVE-2024-43800 — serve-static: Improper Sanitization in serve-static CVE-2024-45296 — path-to-regexp: Backtracking regular expressions cause ReDoS

🎯 Affected products90

  • RHODF 4.14 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:08a046ba8c5a9284e7fc9263f51eee40a5203c5d41c25ac2df555694dbd5a395_s390x as a component of RHODF 4.14 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:6b2cb0576d635bfeef719847a6b3a651b5527a0336fe57548ae609025ddb2016_amd64 as a component of RHODF 4.14 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:984f5852a4793d9883106ccca492b1daab60d3c85f21ad667f92efbe8e5d1c50_ppc64le as a component of RHODF 4.14 for RHEL 9
  • odf4/mcg-cli-rhel9@sha256:0f8ea96fc58192660d845131c760a258a8e33fc02fc85884aa9be5ea07fd5e26_arm64 as a component of RHODF 4.14 for RHEL 9
  • odf4/mcg-cli-rhel9@sha256:1f9ed27e2bd7b881aa5bc06571cf1cd459d577746e01f388bef01679013958f5_s390x as a component of RHODF 4.14 for RHEL 9
  • odf4/mcg-cli-rhel9@sha256:a665d06e0ec627db26cf47e0e19a36793f185fbf7dcb2a756983b0c08d041a09_ppc64le as a component of RHODF 4.14 for RHEL 9
  • odf4/mcg-cli-rhel9@sha256:e33c0ee4709e501d0a25c9da0089cb28b79ee80d28706465b55b9b17f807d260_amd64 as a component of RHODF 4.14 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:8d8230c10fa25e17fdac866971ecbdcec369e998f4f965eab27abab46d1eaf4d_amd64 as a component of RHODF 4.14 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:8dbb2f97682ab4a0f88e4b63485738f591a002faded8d1e5a01f918abd0a22b5_arm64 as a component of RHODF 4.14 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:bc5578e6f07cd0692abd897bf25b99361f1044a10ddcefefae13d3af338b3d58_ppc64le as a component of RHODF 4.14 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:cf73fc2fa89884542a1f0e333bd9e1dd587a05e86442d67a316cd1c1d26c925d_s390x as a component of RHODF 4.14 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:a42cd3a47eae7d05c44b438321da63faaee8274e4099171ec30c75005526f05d_ppc64le as a component of RHODF 4.14 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:a73e671a9db5b88691800cefb2c903e7012499bc857e6cca62af958a35b5eab6_s390x as a component of RHODF 4.14 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:f034e4be8b4e4e29ae79b12b800bf9ea682fa006a3ba6e84f42e06167a239750_amd64 as a component of RHODF 4.14 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:0af9a6828abb53c18dae132b6a91862a85b5ad0b3f3ffbded002955af2fd04e2_s390x as a component of RHODF 4.14 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:1e20312fdd047dfd87b67d0bdc6a493df330c58671bcd0e078f22686df4a8d66_ppc64le as a component of RHODF 4.14 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:bb82af60a467551305c8628e6c8bac0b0d01637a0fb04b4142e69c90d3003434_arm64 as a component of RHODF 4.14 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:fc98e8793dac5fcdb663967a7fd27c03d4cbb38295a5b1138f30cc1936bec92b_amd64 as a component of RHODF 4.14 for RHEL 9
  • odf4/ocs-client-console-rhel9@sha256:3d2aba1307256ae6ee3a2dffaf0d175f7d204f7484712c1ec083d74203de2cb8_ppc64le as a component of RHODF 4.14 for RHEL 9
  • odf4/ocs-client-console-rhel9@sha256:5e05fc58b6b37b6e6f45a0042d3b167760fcc3dd5d14f4620a889d5feb90ae76_amd64 as a component of RHODF 4.14 for RHEL 9
  • odf4/ocs-client-console-rhel9@sha256:f5976d4c7303ddb27dd91f33517af1e74cdf42e3539219c30c0c87408a085f95_s390x as a component of RHODF 4.14 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:23aad767b433979e8465b4420278bf41a729e32530f80ef3bb3e98466afca95f_amd64 as a component of RHODF 4.14 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:3e398e98250d9638c8ad75bf88ae2cb936d499c1ebf0d0cc897ce37fbb25b42b_ppc64le as a component of RHODF 4.14 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:59921e0c5c495c57a8efd9022b95bf0964fff99ba6f207cd49ed3b0112189f45_s390x as a component of RHODF 4.14 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:12fa0510c846a2f2d7984ab844faf117848aa9b70bf1642e140a20729fea3b4a_ppc64le as a component of RHODF 4.14 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:aeabac054147c3be143ddfcc48702332a58d17a31e461c1cf863fa273a5364e0_arm64 as a component of RHODF 4.14 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:afcecc910feb27ffc8c48ce6aa52f2d305fd785b7a31e8d035d14f771f9993ae_amd64 as a component of RHODF 4.14 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:f0fab98314e526b530a06a4859cab011647358ea65827288bd12d97ac1cf6e38_s390x as a component of RHODF 4.14 for RHEL 9
  • odf4/ocs-metrics-exporter-rhel9@sha256:06c5ad2463ba39e95ad251fd388b2c604deec27da05ef2c4d98952173eb56787_s390x as a component of RHODF 4.14 for RHEL 9
  • +60 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: No mitigation is yet available for this vulnerability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (11)