Red Hat Security Advisory: RHODF-4.15-RHEL-9 security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2023-44270 — PostCSS: Improper input validation in PostCSS CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file CVE-2024-21528 — node-gettext: Prototype Pollution CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html
🎯 Affected products90
- RHODF 4.15 for RHEL 9
- odf4/cephcsi-rhel9@sha256:afd08e6db4609a733b6f8e5833e880bb990195bfa514ddc3aa4575eee0065b55_ppc64le as a component of RHODF 4.15 for RHEL 9
- odf4/cephcsi-rhel9@sha256:c9720ff854b27882dde55e3cec487f6f6f78630ccb427870e848b04689d95417_amd64 as a component of RHODF 4.15 for RHEL 9
- odf4/cephcsi-rhel9@sha256:d655f9bb7f59a1312674fb56ed799bd413f95a29b58e194efb097f9547ca9320_s390x as a component of RHODF 4.15 for RHEL 9
- odf4/mcg-core-rhel9@sha256:2ec44c4660966041f97ab17c90faac384ae286e88ae2cf28c8c43397ce59d4e0_s390x as a component of RHODF 4.15 for RHEL 9
- odf4/mcg-core-rhel9@sha256:42f249a0b7bce82732387362a4e135140bd6338d30d65ba18df97a3e6d752f23_amd64 as a component of RHODF 4.15 for RHEL 9
- odf4/mcg-core-rhel9@sha256:852b4d896884f0d4e81f9d8a29335953a01153771ff885adba95ba4fadaba2df_arm64 as a component of RHODF 4.15 for RHEL 9
- odf4/mcg-core-rhel9@sha256:e086a3568ee8a53a0f3c1bb1616375bc092a3692de686c1004eaf9bbefa52892_ppc64le as a component of RHODF 4.15 for RHEL 9
- odf4/mcg-operator-bundle@sha256:259d26c041a55ba5c5700ab8c258c4afa8665e7db3c6b6e6d980bdce33cd0e94_ppc64le as a component of RHODF 4.15 for RHEL 9
- odf4/mcg-operator-bundle@sha256:6020166a85745a92f89bc8070d41e5581c11d7758a0560fe90c7808fec3b4072_amd64 as a component of RHODF 4.15 for RHEL 9
- odf4/mcg-operator-bundle@sha256:f81256fda5d97ea6426b7826215092896c8316b1294bb91e68dcef3775916615_s390x as a component of RHODF 4.15 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:376f84cf689b35dc6de959679829a279b134676a1d3e7e9f557668b21110eb73_s390x as a component of RHODF 4.15 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:7ac459cd93f79ca61c4aa6c5f42365bad4e3adda2712cf38f2c9123730171d3e_amd64 as a component of RHODF 4.15 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:7b7c2e424cbebe7b570ff5883cb9d491a5ddeb84013e34fafbcd973645a3937c_arm64 as a component of RHODF 4.15 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:9fc0d8f34c48b256704f43d4b6b08258a31a37409499c0e5125287118c2add69_ppc64le as a component of RHODF 4.15 for RHEL 9
- odf4/ocs-client-console-rhel9@sha256:0cada446d73b02279aeb4cac590b77d170e11fa69a6fb95c5fbb73a7a986673c_ppc64le as a component of RHODF 4.15 for RHEL 9
- odf4/ocs-client-console-rhel9@sha256:883751a0d9e0caaa601fcb6574fc7da28a992e204908d7259213cf8d20e4f710_s390x as a component of RHODF 4.15 for RHEL 9
- odf4/ocs-client-console-rhel9@sha256:a7e3ee8a21cac9f7fbf6a99a71b133a71750c2de7bf760d06cb08998472334a3_amd64 as a component of RHODF 4.15 for RHEL 9
- odf4/ocs-client-operator-bundle@sha256:8a5f0ba5ea797e1781ff5bf448bdeda379b8522f5affee0e17f65af47ff462fd_ppc64le as a component of RHODF 4.15 for RHEL 9
- odf4/ocs-client-operator-bundle@sha256:b0cf9cb5990f0c8be8670adb2d81f7fc294bb3bfd7ab510f0b41e97f77e5b117_s390x as a component of RHODF 4.15 for RHEL 9
- odf4/ocs-client-operator-bundle@sha256:b5c18f42e9edffea0ae461219ad54911d8f7f6976a640500c03361d923dc238b_amd64 as a component of RHODF 4.15 for RHEL 9
- odf4/ocs-client-rhel9-operator@sha256:0a3122df910aaa8f8aa9b6f9cff3151d2f26c4cdde4f089afbc74b327f7cdf49_ppc64le as a component of RHODF 4.15 for RHEL 9
- odf4/ocs-client-rhel9-operator@sha256:4fbe08867ed4ff746697a0e984e394fe53c1f91f0f2d8c6c1c154712067ce06b_s390x as a component of RHODF 4.15 for RHEL 9
- odf4/ocs-client-rhel9-operator@sha256:7e35db3cb5f2fb7a4804b541c46b3e53dea3c031a66356ab25519fe26679e281_amd64 as a component of RHODF 4.15 for RHEL 9
- odf4/ocs-client-rhel9-operator@sha256:8d568b564063ffe2e0e165fe8abd32764c4ccd37a66e12332c37f83d734a04c0_arm64 as a component of RHODF 4.15 for RHEL 9
- odf4/ocs-metrics-exporter-rhel9@sha256:7f867f41480a582339915abf6dd28bf72ab61b18259f25ba31c973f376babe15_ppc64le as a component of RHODF 4.15 for RHEL 9
- odf4/ocs-metrics-exporter-rhel9@sha256:c77741fdcd40ffc86046f1b0825f7739de6b333b450d09c9757a19ed4dd22b78_amd64 as a component of RHODF 4.15 for RHEL 9
- odf4/ocs-metrics-exporter-rhel9@sha256:d5cc67cf06c7fc1736a107d9d166689e1785d9174c8a8b15c5b820c63e3facae_s390x as a component of RHODF 4.15 for RHEL 9
- odf4/ocs-operator-bundle@sha256:4ab804c7b47c6e67b0765d9e8c8c4eae2656fecda26a9b3178a46d5619cc2818_ppc64le as a component of RHODF 4.15 for RHEL 9
- odf4/ocs-operator-bundle@sha256:4ae63ccaaf14f1709243877b2253b72c0e8d2401351d44c010c211130a500515_amd64 as a component of RHODF 4.15 for RHEL 9
- +60 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: There's no known mitigation for this issue. Red Hat recommends to not parse untrusted CSS input using PostCSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2025:1865
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2294000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2311014
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2326998
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2333122
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1865.json