RHSA-2025:1983MediumCVSS 6.1

Red Hat Security Advisory: Logging for Red Hat OpenShift - 5.8.18

Published
March 5, 2025
Last Modified
August 4, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2020-11023 — jquery: Untrusted code execution via tag in HTML passed to DOM manipulation methods

🎯 Affected products5

  • RHOL 5.8 for RHEL 8
  • openshift-logging/kibana6-rhel8@sha256:11bfe43b2b6372dfedee47ef10ec0ec67bb7070265f579dd512a36e2ff691ff6_s390x as a component of RHOL 5.8 for RHEL 8
  • openshift-logging/kibana6-rhel8@sha256:3edcb9e5f595f43560c2d1a9cd643ba3a47052d64d02ffb239aa514444c7ffca_arm64 as a component of RHOL 5.8 for RHEL 8
  • openshift-logging/kibana6-rhel8@sha256:571d43bc602450e0883ec5aa3e7d44a00413be545ab4c0a67db48cd7c1e77b3b_ppc64le as a component of RHOL 5.8 for RHEL 8
  • openshift-logging/kibana6-rhel8@sha256:fff31521cd7e8533be31f39eda05d47fb8986fbeb144819cec3761e3b1e1ba32_amd64 as a component of RHOL 5.8 for RHEL 8

✅ Remediation

For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html For Red Hat OpenShift Logging 5.8, see the following instructions to apply this update: https://docs.openshift.com/container-platform/4.13/logging/cluster-logging-upgrading.html Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

🔗 References (3)