RHSA-2025:2700HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.13.56 security update

Published
March 20, 2025
Last Modified
August 24, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2024-56326 — jinja2: Jinja has a sandbox breakout through indirect reference to format method

🎯 Affected products43

  • Red Hat OpenShift Container Platform 4.13
  • openshift-tech-preview/metallb-rhel8@sha256:b9d32a7728e462b213ab248f876a3ad3aeb41ea739382db298e44a2a83902f82_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/frr-rhel8@sha256:e9f24d9d7a2b838371c6ebfbb790645e2067caaa49c7721475b5392d8ee6ba8b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:fac56768e040b35ced138101b58f4057b64ca70d27a848a556b72304d5d1c026_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8-operator@sha256:6bd6587fc2bf20081a31faaf83643283bc9fc7dfa198b21576cf860dfd3d43e6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/metallb-rhel8@sha256:b9d32a7728e462b213ab248f876a3ad3aeb41ea739382db298e44a2a83902f82_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-ansible-operator@sha256:96f9aacbf76f85d57a0145079b7c90dd460a984c54884838b3a42ef56bf32cc3_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:62f775433ee8bc7d58babaf274a35ead4e88349c9811de6dd38cd743ecc89baa_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:81bfe4c9e4fd10ac13d3516b93ac1ae90b29aef5a5c4580839552e6f6562fb66_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cloud-event-proxy-rhel8@sha256:00be059450e7a7d317480e2ad3fb6a37eecf34e6e3390322b9bf96cc36a14387_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cloud-event-proxy@sha256:00be059450e7a7d317480e2ad3fb6a37eecf34e6e3390322b9bf96cc36a14387_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-capacity@sha256:422cf44cd73b9c124f7a6849bfdc877187a422d25efda278bc7b0517ed7f5cc0_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-kube-descheduler-operator@sha256:09795d9734db20e3b5c2758560c3b260043b78142969c62984fab8b29278a4d5_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:09795d9734db20e3b5c2758560c3b260043b78142969c62984fab8b29278a4d5_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-cluster-nfd-operator@sha256:57d91503c7b43c97032f3514846235438a821f379fe9c677f252e7ff8dfadd4f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:5ec670e80165822e16449db2912a3b4f763c9d3d86776e7e163c56cd186f9141_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-clusterresourceoverride-rhel8@sha256:fc94c0b78343138e097e956a28af98446a92f33ca48417d7dca595e4f121c036_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:177803d561254946e6ca50cb584893639093d425a6621a164238d49a215dcf43_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-descheduler@sha256:21eeca620f47f40adb67d3467b6d8f02dd99ebd03633eb1ef968ac77811823a5_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-egress-dns-proxy@sha256:56126a7755ec108e51c063c0ddf6b59a5afff17b68dc9f8f37575510e2d2e19d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-egress-http-proxy@sha256:06051a1bcf77d309fd3b45cb02bdb9188dabe7178bef67acea9418c18a1afe2a_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-egress-router@sha256:4204c6a89528f969cf2023186f4222d4b156f72b8c1b382ef724a4b637080691_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:ae9bd2beecf80057431f7815b8eca50545edb2501ba235cb9fce3743559f3abb_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:ef2201a5db3b7c61ffc037160360b8063c779a9a464e9d7c0e41e01a70a17b03_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-helm-operator@sha256:c9d5e54ff06249ef5afb359de59d0c390aa59880a03c36605ab0670e7cc9cf30_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:0911b143fe2aa04606ad459d07bf6e7ff72125d5057644e1cce05cad2273dab1_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-local-storage-diskmaker@sha256:cd13b64f632d69d01f4817b4544485995a898ae212b0bceddebb217b893eb756_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-local-storage-mustgather-rhel8@sha256:926768fee56c9f82555eb584ee1712b5f9a48b2cca030b215647d467a005ec71_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-local-storage-operator@sha256:5ca97ea653819810088592d79eafdfde0d266daa4db26ead30b8fa6d2365c846_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-node-feature-discovery@sha256:095a201004ad04eef16723be42e445da35874b0e46bdcad0d547dee2066a5797_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • +13 more not shown

✅ Remediation

For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/release_notes

🔗 References (5)