RHSA-2025:22415MediumCVSS 6.5

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.17 security, enhancement & bug fix update

Published
December 1, 2025
Last Modified
August 22, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2022-0155 — follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor CVE-2022-0536 — follow-redirects: Exposure of Sensitive Information via Authorization Header leak CVE-2025-5889 — brace-expansion: juliangruber brace-expansion index.js expand redos CVE-2025-7195 — operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd

🎯 Affected products81

  • Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/cephcsi-operator-bundle@sha256:df248fc03d492a22ad9860a382eab61ed872474bcfd599c1655f85731bde2bc8_amd64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:0b3b8d6d1c0cd176ab61c529ab42e7a12720f6a42bf89ca1568656bdbc463310_arm64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:12bd5b3aec0dbd7bd29e10956eae9986ab95591918e4331ef495ba9480e13338_amd64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:8644ff17cdb6427db074a2c5d1aa3ec2168524fa2b0a2cc86095321cdd7e116e_s390x as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:c7705b99cc2d009d2e0f09fd5051f8b971af863384c2b71e4923f52f3430febf_ppc64le as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:4732e19283a907e1a987590a0815e4c7b95c80218864eb6ae7f0393867a28e2e_amd64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:b85b442e7736f1513f25a7278881b5adcfc04fdf0e55546358824459efdbd820_ppc64le as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:fa22abd3771012d249add9357a05ac7adb6d41783f09fb0920cbc340a3134739_s390x as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:2a9ecf79a8209fb80fc189c2a05b68ebb3874dd2e1c404361f3b26533188e6a1_ppc64le as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:b0d4c9692b9c2ea9ffa0af5bfe5fa3d9a7f2804702a5c41e4134cc1e67dad9ea_amd64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:c934f1d948599bb2ab0f3dbf567b965dac1f2253c51b922cb6df5584592f0685_s390x as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/mcg-operator-bundle@sha256:06ac023fb57eccf57a7e2b1294fb25ac10d6685a6aedf931dc3947f921361574_amd64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:57597555a31a799fec3dfbdc43949a8b3b1fb9bc02ef8a7990982335ee94f71d_arm64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:a8135ff473a1f8fa10a7e58258a6e355e58d6df2a89caf9c15d7c2c437d5cb8f_amd64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:c0a8b08176be1737fb15f9e68444b7fe56678071518253ed3ad82c9f9c0bb8d5_ppc64le as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:f8b580c7ae457d436cca8bb637e5bb6dd8a42e6af32ff10416b6874bc2bc8357_s390x as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:00d18b2cf2c778dc1f4a6ec4502038bec5138ef7624ef13a7360d48745a315f2_ppc64le as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:166573d2a6d90fe041bccb6ccb867e487131fce54ddf6e52bfaf79859bcd9cb7_amd64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:52b41ec0e8f6f6e5f39aa2f1c173eef364fcae6e78a8c6091f0c6b3583221034_s390x as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-client-operator-bundle@sha256:4efcabd8ca12ce8ee58353db9333702fc19f2e7c67c88a593f1f63071de070c9_amd64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:4b3115829f2443bc90d15421da6e0679d7f9364639a46bd43aa858ec5e2109f7_s390x as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:5a98709f9dd4228af8d0426d3afaacbf4fdbb22afcc013187a03612a2fd0cd96_arm64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:b2ec7b94fa8e3e95fbe9195f0ae886d85fa6edc592949b6d28eb67e5e5cd1654_ppc64le as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:c9ba48b021b0ff0ee11b8862234624e1321f607ac622808108da8848f805c76b_amd64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:e661ba3760dbd154ca7fcac8ceb39a50403664e712f43a93c4732b7e078de7aa_s390x as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:eed37ac242b6eac361d12ac61bd1d9be070ec6243dc2724c778284aa21db815c_amd64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:f408b197483b49725f11757d3adac645353cfdafffff59298aca57bc012a538d_ppc64le as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-operator-bundle@sha256:e5602e33c3f219ee6294e1438a77c5cf439bac2897d32f052fc7bcb35aa00ee6_amd64 as a component of Red Hat Openshift Data Foundation 4.17
  • registry.redhat.io/odf4/ocs-rhel9-operator@sha256:55e3e523175182a9f5536e3d331ad57596b5d28d51e7177efb875d16fa81ecc2_ppc64le as a component of Red Hat Openshift Data Foundation 4.17
  • +51 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.17/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf Workaround: Currently, no mitigation is available for this vulnerability. Workaround: In Red Hat OpenShift Container Platform, the following default configurations reduce the impact of this vulnerability. Security Context Constraints (SCCs): The default SCC, Restricted-v2, applies several crucial security settings to containers. Capabilities: drop: ALL removes all Linux capabilities, including SETUID and SETGID. This prevents a process from changing its user or group ID, a common step in privilege escalation attacks. The SETUID and SETGID capabilities can also be dropped explicitly if other capabilities are still required. allowPrivilegeEscalation: false ensures that a process cannot gain more privileges than its parent process. This blocks attempts by a compromised container process to grant itself additional capabilities. SELinux Mandatory Access Control (MAC): Pods are required to run with a pre-allocated Multi-Category Security (MCS) label. This SELinux feature provides a strong layer of isolation between containers and from the host system. A properly configured SELinux policy can prevent a container escape, even if an attacker gains elevated permissions within the container itself. Filesystem Hardening: While not a default setting, a common security practice is to set readOnlyRootFilesystem: true in a container's security context. In this specific scenario, this configuration would prevent an attacker from modifying critical files like /etc/passwd, even if they managed to gain file-level write permissions.

🔗 References (8)