Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.15 security, enhancement & bug fix update
🔗 CVE IDs covered (4)
📋 Description
CVE-2022-0155 — follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor CVE-2022-0536 — follow-redirects: Exposure of Sensitive Information via Authorization Header leak CVE-2025-5889 — brace-expansion: juliangruber brace-expansion index.js expand redos CVE-2025-7195 — operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd
🎯 Affected products73
- Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/cephcsi-rhel9@sha256:1d75f5d047a30a5d80df63d6201cd5550c8aad5d000c079f9d8c9a5c62ae45ce_s390x as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/cephcsi-rhel9@sha256:78175febe7b181ade5054857d20b097797663c72cb17cbae4203958e8a351329_ppc64le as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/cephcsi-rhel9@sha256:7a1e2d4864765f19d3e82990d547c5afd352bb69e8eede1903999bcca13f25d7_amd64 as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/mcg-core-rhel9@sha256:308cd8acade8e07b3183bbe8735b724b866a7337491afc78967eecd2c812d5e3_ppc64le as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/mcg-core-rhel9@sha256:8ed89037982928b39705d3554f51012c537bef9994e2895511a8a356d735fb2a_amd64 as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/mcg-core-rhel9@sha256:c9cfe4871323f9cf38c238bca0550c26f7b4e788a0a7b8d052d8f1fe549c6a3b_s390x as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/mcg-operator-bundle@sha256:3e8bb9b6a858cd72eb86824d5da7eb1e5b0f47753a6749a349ff50e9c25e38e9_amd64 as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:342ec40b4be75a43a6dc9bd86bdd684ffad05c04e177a173273f1d892e2501dd_arm64 as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:471378c4190b89eabe298a7fb4b77ddfd8fa1497b68a64bd178e6eb9467f8717_amd64 as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:8b739d8102a7af6efbf3435d44efd5d00798782109c106d91aeef9f5d766db2b_s390x as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:924aced94d90081d287df423bdb15aacea4b3bc5fd850522aac225e6448d0f5f_ppc64le as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:2012c48688b519ce45f08e1392fd886400a1782ea4bf942e434b4281cebca64e_amd64 as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:37e578ff98671dcbadae9e613512600c8ecf9c1017bce3ce00ddba78239485cd_ppc64le as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:d53c5343851957d291397d11fb14f4b52a1b0e5dbd9a305a3eaf66c45e9b6228_s390x as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/ocs-client-operator-bundle@sha256:24f3379ca7463c985ec60f962df885df9c808ea85c8d9e7a4750d9013488eaa3_amd64 as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:08df676115e46d1dea0c175df6e56f4501aa79d9590ed9790e1d218994999839_amd64 as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:dba72b4adc377084e2fe0ea84c2849fb3101e5d3bb9bc3ee261df6391bd10da2_s390x as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:e180ab9a046e9a14f8c537d387879a96c5013aa784221eb976b0b08fb9e1f7f8_ppc64le as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:e9fa24dc675a9061b4fd8b8bcc16e0e87f1beb89df2ad770f7b19fb935052cd4_arm64 as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:37cb9c23e27da0c54c36bd90bace10bc21406529568deb6436dfbb9bb686dfbb_ppc64le as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:65faa431e4154804f3b3330e37bf97ebfc4a5fbe2ece950e54a50827dd1848e7_amd64 as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:d79168a44c5789d77d249f5ec981d36345cfbd834ee6cef2de0eb8d90e8bf308_s390x as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/ocs-operator-bundle@sha256:e7f5897e36bb09fd3414c0720863eef0cdcc695ad33de4ade9ba5e85ce17f5a8_amd64 as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/ocs-rhel9-operator@sha256:2afaf7feceda2596f257888a5cc5dd19293252da973d4988e00a21c50aa601c4_arm64 as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/ocs-rhel9-operator@sha256:49b4149ccd1bc815843c89e3cb5bc49a0faa67d8966e807e64375ec0c4175e26_s390x as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/ocs-rhel9-operator@sha256:4b1ccf7e715bc66b0e205e6db3ba587594c003fefc3de3508cb49f0e5daefeef_ppc64le as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/ocs-rhel9-operator@sha256:6b47f30899b9eaef4a08de84be1c785a2d5e189914d270f3a50968238690ad8f_amd64 as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/odf-cli-rhel9@sha256:43232acc4c36c387bfcf4eff514d2bbac42c6baf4aa1a9921abd04f8a05ab6bd_arm64 as a component of Red Hat Openshift Data Foundation 4.15
- registry.redhat.io/odf4/odf-cli-rhel9@sha256:7b82430d91bd92f7103b73f39e1eeee300b036cf2dcd24bba4d8a6c73585636e_s390x as a component of Red Hat Openshift Data Foundation 4.15
- +43 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.15/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf Workaround: Currently, no mitigation is available for this vulnerability. Workaround: In Red Hat OpenShift Container Platform, the following default configurations reduce the impact of this vulnerability. Security Context Constraints (SCCs): The default SCC, Restricted-v2, applies several crucial security settings to containers. Capabilities: drop: ALL removes all Linux capabilities, including SETUID and SETGID. This prevents a process from changing its user or group ID, a common step in privilege escalation attacks. The SETUID and SETGID capabilities can also be dropped explicitly if other capabilities are still required. allowPrivilegeEscalation: false ensures that a process cannot gain more privileges than its parent process. This blocks attempts by a compromised container process to grant itself additional capabilities. SELinux Mandatory Access Control (MAC): Pods are required to run with a pre-allocated Multi-Category Security (MCS) label. This SELinux feature provides a strong layer of isolation between containers and from the host system. A properly configured SELinux policy can prevent a container escape, even if an attacker gains elevated permissions within the container itself. Filesystem Hardening: While not a default setting, a common security practice is to set readOnlyRootFilesystem: true in a container's security context. In this specific scenario, this configuration would prevent an attacker from modifying critical files like /etc/passwd, even if they managed to gain file-level write permissions.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2025:22418
- externalhttps://access.redhat.com/security/cve/CVE-2022-0155
- externalhttps://access.redhat.com/security/cve/CVE-2022-0536
- externalhttps://access.redhat.com/security/cve/CVE-2025-5889
- externalhttps://access.redhat.com/security/cve/CVE-2025-7195
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_22418.json