Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.14 security, enhancement & bug fix update
🔗 CVE IDs covered (4)
📋 Description
CVE-2022-0155 — follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor CVE-2022-0536 — follow-redirects: Exposure of Sensitive Information via Authorization Header leak CVE-2025-5889 — brace-expansion: juliangruber brace-expansion index.js expand redos CVE-2025-7195 — operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd
🎯 Affected products73
- Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/cephcsi-rhel9@sha256:931fcca9e7cb6f6c7454a72b533cbe4d767438e374848b846f079a3c2d323901_amd64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/cephcsi-rhel9@sha256:b4568ee6f890f98c1ac67b7115931a0f16bb1d69f3863ce554efddf64ce7b765_ppc64le as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/cephcsi-rhel9@sha256:bc983cfa30512d0dbd5742a998659e0e87c28e9d32817397478190da8508130d_s390x as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-cli-rhel9@sha256:0a88403bb113a735853cc289bad5c2b5e650e5f9d28e28cf635c2fef808025b1_amd64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-cli-rhel9@sha256:13b0299a3e045cc02e6d864398e3676b1dc038504fab8993a92b8b8fdff252c6_s390x as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-cli-rhel9@sha256:46bbbf2af16ac78fccadec959ee02a1036cef23acaa5db93c7d95b7ca6a05c75_ppc64le as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-cli-rhel9@sha256:d46557077f9eb02cfc217de08e3c806d92cc84f885e27484b6f0cdc3af108332_arm64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-core-rhel9@sha256:109ce61c700758e5057d2b465c9820c05f2d51b8f541b70c1b1bcf39fc872d35_amd64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-core-rhel9@sha256:152c336c76cc69fc11cd6d3957c781c8d1c733a3cbead2448efd202b35d034e2_ppc64le as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-core-rhel9@sha256:1a8aa05a3f37eff50915cdec070605872f17f86463285dcae212ab4094816452_s390x as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-operator-bundle@sha256:fe8adb43bed33a29cc8c43bfd717c4659a0c75e4a2b483e1e6f35d7fdd599cda_amd64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:13454f2f70870d6765f740f36582cdf8139c9ed4c0c38e5f8981eea1374771ad_arm64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:ab2921016d982438eec637035fe678a842757b9822bf6f80936137825dacf45b_ppc64le as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:dcad74db55ead7c9c264415d467b08527d3beaf1b079a28ee7108c032a94ea80_s390x as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:f6bb9ef4fdc334383afeb77f5db81543ed3657186402912c374cefdf4e90588e_amd64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:0a0e70953d2217d929b55a7a7a4c1e49c7e5f6b196b693312c252bfec2dc3843_s390x as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:2e3bcf4dcee937c986ee53ada32dc1ee7e5bdcbd161bfbc942cd6061507f13b3_ppc64le as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:e529edb5b01923fc4c44fc8b999ca05719365c2e9ea13e579ecd29e4b4c7e02b_amd64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-client-operator-bundle@sha256:0ebe7fcb83c96197de46898b5bcaf229713b69db51132b8b82b8f9ad2fab1215_amd64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:4c3a738aa7e83a7aea9161c4ef48624a275756531a3d67b13e59b600a4e644ea_amd64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:5bb9afd3185ec19f4957fbe3d195414c02c8e0bd94d6e016525df326bc40c1e6_arm64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:645d5fca647a051a1a23a25f577aa4a7d6520611c97c5232868a49e41156af9e_s390x as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:846f481d6d57e4306f4c53d9ae90c6e9e6d0af1006b7f999c4bc392b25b0183d_ppc64le as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:2f3828b6ad0cdf73db157daaea35e750000f0aa2741b7e5aa679253ba76f098b_ppc64le as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:d3850e64b6707d4fa8c87efd652e4b06ee122c58fe43040b371295626f7d3784_s390x as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:daed8221087db9480c473be7564d9cd327ff9f958971301cc6229dc4079005f9_amd64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-operator-bundle@sha256:1296deea12ccf97ae0cf45ea3a5c2540ebf82fac3308905044b95b163ae15004_amd64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-rhel9-operator@sha256:00cb6923e961942f4beabe19a6ad142dbff62929996728c664a1995fc76fcf8a_arm64 as a component of Red Hat Openshift Data Foundation 4.14
- registry.redhat.io/odf4/ocs-rhel9-operator@sha256:a73d74c5aad19c476d2f6be7bde6763675d68342021e9654dffe4303cf8d2a2c_s390x as a component of Red Hat Openshift Data Foundation 4.14
- +43 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.14/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf Workaround: Currently, no mitigation is available for this vulnerability. Workaround: In Red Hat OpenShift Container Platform, the following default configurations reduce the impact of this vulnerability. Security Context Constraints (SCCs): The default SCC, Restricted-v2, applies several crucial security settings to containers. Capabilities: drop: ALL removes all Linux capabilities, including SETUID and SETGID. This prevents a process from changing its user or group ID, a common step in privilege escalation attacks. The SETUID and SETGID capabilities can also be dropped explicitly if other capabilities are still required. allowPrivilegeEscalation: false ensures that a process cannot gain more privileges than its parent process. This blocks attempts by a compromised container process to grant itself additional capabilities. SELinux Mandatory Access Control (MAC): Pods are required to run with a pre-allocated Multi-Category Security (MCS) label. This SELinux feature provides a strong layer of isolation between containers and from the host system. A properly configured SELinux policy can prevent a container escape, even if an attacker gains elevated permissions within the container itself. Filesystem Hardening: While not a default setting, a common security practice is to set readOnlyRootFilesystem: true in a container's security context. In this specific scenario, this configuration would prevent an attacker from modifying critical files like /etc/passwd, even if they managed to gain file-level write permissions.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2025:22420
- externalhttps://access.redhat.com/security/cve/CVE-2022-0155
- externalhttps://access.redhat.com/security/cve/CVE-2022-0536
- externalhttps://access.redhat.com/security/cve/CVE-2025-5889
- externalhttps://access.redhat.com/security/cve/CVE-2025-7195
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_22420.json