Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.18 security, enhancement & bug fix update
🔗 CVE IDs covered (5)
📋 Description
CVE-2022-0155 — follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor CVE-2022-0536 — follow-redirects: Exposure of Sensitive Information via Authorization Header leak CVE-2025-5889 — brace-expansion: juliangruber brace-expansion index.js expand redos CVE-2025-7195 — operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd CVE-2025-22150 — undici: Undici Uses Insufficiently Random Values
🎯 Affected products82
- Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/cephcsi-operator-bundle@sha256:d273d52e59706f54e1f5382119db5f50b462281fba160dab6d85b57707b45eec_amd64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:5ee6284d6354e4e55f1ee7eb5a79b833aae6e31bf42bf185c4192e5d373f06e7_amd64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:7c02ce667bc7b6693596ba249e34d7233a95fdb1966ce317927b2363518a564f_ppc64le as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:eb1067cf493864c4ca48459b2f9adf0964b3849564743a17e7a3686e925e448f_arm64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:f4615211c16cc89f94043e2588400957b8fd225f233c86096542ac1364678cf4_s390x as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/cephcsi-rhel9@sha256:1690d6c99f4626289bcdd78c8521edffb61c91da1a45aa2eb2b6ab2af137b7c1_amd64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/cephcsi-rhel9@sha256:1ff67f3ff46b59b86c2f29596008440da7da8d594005881c65d6d4ab645aefc6_ppc64le as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/cephcsi-rhel9@sha256:b251e7b26d4a6f3443d6d795a4d92992b5f79d56e5561477648eabae286d7641_s390x as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/mcg-core-rhel9@sha256:87f5569806a8960520bab78d69514f2e2061b2ad69040cf7c164a5037c27e6bf_ppc64le as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/mcg-core-rhel9@sha256:c8dce4a25f10645edc649576e995b2b6619c8bc39c2c30d3cffbe3a3c3a86b35_s390x as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/mcg-core-rhel9@sha256:e0d3839cbb1734c0e224e0c076c7c8b4d0e0888e31989b8a6a611418ea2c72bc_amd64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/mcg-operator-bundle@sha256:6d7720076a49e7e35b52a84c98d858a0c7b767ccad79ad3cfbf721419053669a_amd64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:00bdcca61bc8765fbbc838deeb86392ce25c72f0170241c270484ec9b77bd263_arm64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:852442ee591c566acde876d1101b89f6009f186f6f705bb128754b2ed0043d46_s390x as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:ac8d47727a66b68185bf77848b27b8e5a9c41a023cb6f424a75369b6e4b500a7_ppc64le as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:c6eb556ecea92be74c6175061678d06bb3006a6ccfc5927d2327ddcf244c934b_amd64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:37d0208891259e9d725fb4146d023c1f0cd0dafbff8e322b7c12621ea25f8c85_ppc64le as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:49f1e7092bdd19f318580b3d4dfc37dbec8435f814b7d1b863ed34a6ba6157ee_amd64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:e9f1e2743fe9930ccb470c6eb8d9e9577640fe6a9ab7a013648e513b6216fa74_s390x as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-client-operator-bundle@sha256:7f8435653f35ea08e5d5e7305a06ad3ebee9ddf04f8c03c3cb34fd6fe1f6f577_amd64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:2bd4927011a029a1dd7ba2baa2fdc759d431550879eddc8813d89cb44cdb2767_amd64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:526abc72ccfa1729a5962911f92da64a3dda4a689421ecdb21c7ad2a049f53ef_ppc64le as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:a492d94ceced107b6b8dc7339cca181875d2245c5f8ac9ecc51979160a341d76_arm64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:f588f9517ac72fb92989f929ad6e643440f709cb4d311974d0e201bfd6b17958_s390x as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:5aad1d226292a42c700e97575eec56040108869acdcb720a9c5b32d02a0035b3_s390x as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:d40189f09ff39240e5e49412c1314d9911fcb957459c7496b215da8c9f758b8e_ppc64le as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:ecc54bc4e8be6f3bfade15c23827e84445acc12c63b4e133cee73e57ac5a42aa_amd64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-operator-bundle@sha256:08d6bef2c472ebd7918a9124ac40e6ac0b834df9a7b4a160f027f511345a7df7_amd64 as a component of Red Hat Openshift Data Foundation 4.18
- registry.redhat.io/odf4/ocs-rhel9-operator@sha256:2abd2d479416e66c6f85e4e883d5e4987bc38f476f907766374784107b89de9a_ppc64le as a component of Red Hat Openshift Data Foundation 4.18
- +52 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.18/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf Workaround: Currently, no mitigation is available for this vulnerability. Workaround: In Red Hat OpenShift Container Platform, the following default configurations reduce the impact of this vulnerability. Security Context Constraints (SCCs): The default SCC, Restricted-v2, applies several crucial security settings to containers. Capabilities: drop: ALL removes all Linux capabilities, including SETUID and SETGID. This prevents a process from changing its user or group ID, a common step in privilege escalation attacks. The SETUID and SETGID capabilities can also be dropped explicitly if other capabilities are still required. allowPrivilegeEscalation: false ensures that a process cannot gain more privileges than its parent process. This blocks attempts by a compromised container process to grant itself additional capabilities. SELinux Mandatory Access Control (MAC): Pods are required to run with a pre-allocated Multi-Category Security (MCS) label. This SELinux feature provides a strong layer of isolation between containers and from the host system. A properly configured SELinux policy can prevent a container escape, even if an attacker gains elevated permissions within the container itself. Filesystem Hardening: While not a default setting, a common security practice is to set readOnlyRootFilesystem: true in a container's security context. In this specific scenario, this configuration would prevent an attacker from modifying critical files like /etc/passwd, even if they managed to gain file-level write permissions.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2025:21368
- externalhttps://access.redhat.com/security/cve/CVE-2022-0155
- externalhttps://access.redhat.com/security/cve/CVE-2022-0536
- externalhttps://access.redhat.com/security/cve/CVE-2025-22150
- externalhttps://access.redhat.com/security/cve/CVE-2025-5889
- externalhttps://access.redhat.com/security/cve/CVE-2025-7195
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_21368.json