Red Hat Security Advisory: RHODF-4.14-RHEL-9 security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2023-44270 — PostCSS: Improper input validation in PostCSS CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html
🎯 Affected products90
- RHODF 4.14 for RHEL 9
- odf4/cephcsi-rhel9@sha256:01119cd6e5cdc5aed68fd23ad8192925a561b38f049c7d153858407f9263f151_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/cephcsi-rhel9@sha256:875f3639444793baf0783faff34acf22d8266f85bee8fe0fe71debaf0c04b577_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/cephcsi-rhel9@sha256:e724d086d9e0e28c42ce997bb477d2db86e36d1c448050e8b4611b98ad89eab5_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-cli-rhel9@sha256:084c38bd692c8233d1d44484e621b01a840049e497bdcd2af7621d8ce805071b_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-cli-rhel9@sha256:0a9094a597ac62a99593d88fd69926096c95263e9daf230d0335d54ad6de81bc_arm64 as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-cli-rhel9@sha256:5e401b1a41c2fc866705bfc5492e734423f9bf5844f00ef510131f401a2abf5d_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-cli-rhel9@sha256:e314a3e4193deb5187a9fd5c56c70a2b63d55c5ae22f304c01c5ad27114b38d6_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-core-rhel9@sha256:5876a75d34b860e73accd588abdf09cf2e59ff38f47ce9b7f2f002ceb2a7bd5a_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-core-rhel9@sha256:87426cde2a152397e9ee28c52ed503d098924154f257acbe04787ba2a797416f_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-core-rhel9@sha256:9435512b7d2a884db40f3db43d920bd97ca30ed13e40d9edde5c795575af284a_arm64 as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-core-rhel9@sha256:cdc4c487c5c228748e2dfdb280181bcff122cc00f2c7be0eabe917c66c557f36_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-operator-bundle@sha256:15dff59b4e787dc97ce8d773680376d5902db0d86326182dd19f5ec5865ddc85_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-operator-bundle@sha256:3f1d1e16618f28acb70c4c9ed5e6675f2b5e41079ad4d77850b8b3b2e8433b31_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-operator-bundle@sha256:ef15da624e99f6f8e34cefeb7f16cffc13285d597d5f760815c57798e01bddd9_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:433c0d3c5a67ff18dcfc678a3822f8b75f2d7e3893288f0789ff42fd7859372f_arm64 as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:48965c2c3bc1ab26e2d541f9dbf0096d21f8611aa98ceaee12de70d54d004aa1_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:67c617a9b48c9fc683e945357d3a9bc515c6c96f782deaf573e756b42ecddf8d_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:99a092112bb85b1afcdb5c5ed2cf4a0ace07d33efef18a78b83f9ed1ae7d5e89_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-console-rhel9@sha256:07d6dce26001a288dc23f19a04af4407312edc36506ce961abdb7cf44f5017ad_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-console-rhel9@sha256:7d49faa18106a5e4c3c2be4fd4471e1778737dcef54d9c22cbcca33216eddc24_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-console-rhel9@sha256:cf04ad2b6891da8f4e246da41041543817666b18e372e7ed4cc655b3b30bf96b_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-operator-bundle@sha256:38de7a19d4636f17551b2fe76840a61accb2ec4ac39b7b6f815670e25fd085f3_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-operator-bundle@sha256:7467d33d1e7831d991468b2ca6b74e7e0b39c24c9aac3f2ff8e7986e4f58ddc2_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-operator-bundle@sha256:ad6314b15e7eb64b4e3a296dcc618077ec8bed1ecd068e3693781882a2d3f5b4_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-rhel9-operator@sha256:2f2116f744ac245e24da9264fd1bd7ac645b85329717ad9e6681deceb45ae09e_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-rhel9-operator@sha256:78bbd4ab235e453540615037c1074563d588808a9169d9e3f44665d3231d49c2_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-rhel9-operator@sha256:7e7d1c77d57f127557ae64adaf86e54e9aa40a7007f6f68669b4034f480e2a10_arm64 as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-rhel9-operator@sha256:9e7a9d7573c7ad5da4e4c587f1331ea50a36cca88d53ddf601b9b49e82c4c197_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-metrics-exporter-rhel9@sha256:35ec07d822ed1394405049d40bf1acb1c572568590d7ee21e0091e53ebe3043d_s390x as a component of RHODF 4.14 for RHEL 9
- +60 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: There's no known mitigation for this issue. Red Hat recommends to not parse untrusted CSS input using PostCSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2025:1866
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2294000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2326998
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2333122
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1866.json