Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.16 security, enhancement & bug fix update
🔗 CVE IDs covered (4)
📋 Description
CVE-2022-0155 — follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor CVE-2022-0536 — follow-redirects: Exposure of Sensitive Information via Authorization Header leak CVE-2025-5889 — brace-expansion: juliangruber brace-expansion index.js expand redos CVE-2025-7195 — operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd
🎯 Affected products76
- Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/cephcsi-rhel9@sha256:28f2860ac1920009eda82fadd3bd134aa53e410974f257b2d700dd57a5ce55c8_s390x as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/cephcsi-rhel9@sha256:88ee659ec3dee8762aef89123cab66c71e58cf473af2b1f3c9abfff65d645c50_amd64 as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/cephcsi-rhel9@sha256:90e1182faf9159afda95183b6e38b7c6b85135ba1f42cae017a2e3bb79ba577c_ppc64le as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/mcg-core-rhel9@sha256:0a9ebf5ec13dc86adaf99a291d6d97f306e3d2c4efebe330efed45cb243a7eee_amd64 as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/mcg-core-rhel9@sha256:f1c8c40ee99ee53c66bba5a4d81c87f1396097316f31dec48a1646701f41f232_s390x as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/mcg-core-rhel9@sha256:fec08e03cd803c02de22286b1cd985751d39cad6ea355275d3d9970af080815e_ppc64le as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/mcg-operator-bundle@sha256:314b6ae1accb0e88412fdc00e1a9e581008345aeaf81ade060af8a5446a91cd8_amd64 as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:39b8896056e50856d726943e1fe5474737d00729e24c55ea19927516e7f663a0_ppc64le as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:63d7343bc58a15c3100d40a7db1c12684466f0c229b383ffa66f762578bd1c17_amd64 as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:8c9693993390434902aef2af7beb58823b8646dad7f3ac317ec7e7faafde9767_arm64 as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:cca27409fe4da2aa3a6502df29727b023091ef8570934396ee05dd6cb8aa21d6_s390x as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:2157276d6715734095eccf19ee2a3b8ee2610831e6db28db4d1549a45ef1226f_ppc64le as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:2540e7b1d58f9222954796992c82b03706c32b03eb76973a203e9dd6a9fd1614_s390x as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:e6fb7a9352e05748be5085eb685af6ecd4ac6c466fac27f6391b1e801f79c7c8_amd64 as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/ocs-client-operator-bundle@sha256:395181c1caca6c25dd712b4d51fccb4db5053a7601910ac95cac0967745a3bec_amd64 as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:12de253d776c8a2b72966403179650aeee0ea3a4100be45a93b240fcf23ccc17_arm64 as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:68e04debdfcee3d93ec84d87d20e66b09e824d6a184fd794f5521ace2c80ec52_s390x as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:c2f92235f218700f0d19cda4ae7e2d58689f82f4d31e1e97aa446ae6658a7c64_amd64 as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:d76fb81a135d7d65adc9f7c73c891148662810dfb013446bbcd17215dc48ab66_ppc64le as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:57f81dbdd41c7ffba5d245a3cfff9192051443da9e77da67a54df4459f472a5a_s390x as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:b5841b2cd71832edfd9920412c8cc857a2c2e8beef7822a544c5cf418499a9ce_ppc64le as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:be114324106bac45e644e8a4c13dad7699e8808fcaf7da535fe9e7cdc06f1796_amd64 as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/ocs-operator-bundle@sha256:15e462db028474cef4a63a4bbb8ad0aa83d9544672396f3c36c44d015bc6f2dc_amd64 as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/ocs-rhel9-operator@sha256:28fecbad41a6b90ed64ff1ed6d36acf4cf88a8f86131556d6d8ba35766c9a70e_amd64 as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/ocs-rhel9-operator@sha256:81406e5a67aa735204cbb02891f9074ce834e13d9c0225d2ee679dd49e3f3d73_ppc64le as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/ocs-rhel9-operator@sha256:df0da9164ca8e2a2ee10782e016c6de8279eb07e9840b7f6ee55c9173e5c6400_arm64 as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/ocs-rhel9-operator@sha256:e4bf6d76d50ba119227780b6dd86947c760d6195da3bed49b0f6f99a43ea0501_s390x as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/odf-cli-rhel9@sha256:69ae289c4b1a9a51a25813d996d7f14794bcddc39df0512cc6e8effc6e32ad16_amd64 as a component of Red Hat Openshift Data Foundation 4.16
- registry.redhat.io/odf4/odf-cli-rhel9@sha256:87f98b47c63d90a92b3f38ea964d1351832a54e288b39af82a534b577c42b43c_ppc64le as a component of Red Hat Openshift Data Foundation 4.16
- +46 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.16/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf Workaround: Currently, no mitigation is available for this vulnerability. Workaround: In Red Hat OpenShift Container Platform, the following default configurations reduce the impact of this vulnerability. Security Context Constraints (SCCs): The default SCC, Restricted-v2, applies several crucial security settings to containers. Capabilities: drop: ALL removes all Linux capabilities, including SETUID and SETGID. This prevents a process from changing its user or group ID, a common step in privilege escalation attacks. The SETUID and SETGID capabilities can also be dropped explicitly if other capabilities are still required. allowPrivilegeEscalation: false ensures that a process cannot gain more privileges than its parent process. This blocks attempts by a compromised container process to grant itself additional capabilities. SELinux Mandatory Access Control (MAC): Pods are required to run with a pre-allocated Multi-Category Security (MCS) label. This SELinux feature provides a strong layer of isolation between containers and from the host system. A properly configured SELinux policy can prevent a container escape, even if an attacker gains elevated permissions within the container itself. Filesystem Hardening: While not a default setting, a common security practice is to set readOnlyRootFilesystem: true in a container's security context. In this specific scenario, this configuration would prevent an attacker from modifying critical files like /etc/passwd, even if they managed to gain file-level write permissions.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2025:22416
- externalhttps://access.redhat.com/security/cve/CVE-2022-0155
- externalhttps://access.redhat.com/security/cve/CVE-2022-0536
- externalhttps://access.redhat.com/security/cve/CVE-2025-5889
- externalhttps://access.redhat.com/security/cve/CVE-2025-7195
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_22416.json