RHSA-2025:4677HighCVSS 8.2

Red Hat Security Advisory: OpenShift Container Platform 4.13.58 bug fix and security update

Published
May 15, 2025
Last Modified
August 24, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2022-49043 — libxml: use-after-free in xmlXIncludeAddNode CVE-2024-55549 — libxslt: Use-After-Free in libxslt (xsltGetInheritedNsList) CVE-2025-24855 — libxslt: Use-After-Free in libxslt numbers.c CVE-2025-29781 — baremetal-operator/apis: Bare Metal Operator (BMO) can expose any secret from other namespaces via BMCEventSubscription CRD CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing

🎯 Affected products194

  • Red Hat OpenShift Container Platform 4.13
  • openshift4/cloud-network-config-controller-rhel8@sha256:2af0c5f28710eef08d7e795b2f2fd396239446741ad1e1e658554cc5b2d7499c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/driver-toolkit-rhel9@sha256:bf3ce5247b64b65685f59cb0c33b1c933cf3a215d44f019ee79bb83be4be64fd_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/egress-router-cni-rhel8@sha256:4a1882927aa0730aa113759930b4f529ee268c264f17ff912774f7a1d98ca18d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/kubevirt-csi-driver-rhel8@sha256:d7e0ec5ad37bab321ac8a40dcb64384eb3c16ae5e858464ee1c32cb20401f526_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:c02e74a36878bc56a7b415654bfff711c1794ac0a3c3648c5fd2170675ae87da_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/oc-mirror-plugin-rhel8@sha256:54410c3040cb45b528c6c701da77bf3294edc0cbf75c2afd4110b20fca1c59e1_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/openshift-route-controller-manager-rhel8@sha256:cd8cad7979a93f0a3d782643f478ba0b37a36b2c2d1de1ed552718d1bb270985_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:4584e4b91a2c79b2350c1e615099ce652a0cf1f5f6174a573b2db9a77680f0e8_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-csr-approver-rhel8@sha256:40faeeee70ac61a27f15c02a2fe4de5d186cc6caa7a2773dca5b20bd9ac45738_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-node-agent-rhel8@sha256:f89ec093de1ecac1c670bdbbe29fabdc9a49bf579644e577e6b48bfb743f76c2_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-orchestrator-rhel8@sha256:9acd281012ec22619bdb11973382d7c946c29f536594ef7a29a84270fd2e761c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-alibaba-cloud-controller-manager-rhel8@sha256:6b35661834a938fe9accb877934fc523a4782d00e08926577abd4687aa029efb_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-alibaba-cloud-csi-driver-container-rhel8@sha256:16b3ecc755a547774f58334978ed72c6700c898ca06bcd0184d39e830709e707_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8@sha256:47ad1365190ac5eafe893d49d8cf55e057ada01198661d27163f08841e4de5e3_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-alibaba-machine-controllers-rhel8@sha256:24e838680502b2efd46c17b2210f053860c91ba396786b8d5350a553bb6aae54_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-apiserver-network-proxy-rhel8@sha256:88bab056feb7370de294928e88d79505fbff5dfc084ee5f109f6a81bb54858df_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-aws-cloud-controller-manager-rhel8@sha256:c2318383b8ee9cefbd1e4a072c67819045404b125ba0b3167699af6b2e8f719d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-aws-cluster-api-controllers-rhel8@sha256:d28ffcbdfec5913dc17c81451883108f1e7df09ccb3a89cdd69a096927a8e430_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:0f31ee297e5fe72c4d21253c671153b5afa401fb24f90461f24e3183a9e102dd_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:ca6b67a58ba88779d5263fd75700596c2591d9808c6ae14d436401073ba1ab2d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:dd13b3c6fa06cc0f137edde8542422d663ff31d52e0d062cfba8229fedaed19e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:7d795f9d529424252eabcac30a80bb9d8a02aaae37c0563abf35af0f464f0807_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-azure-cloud-node-manager-rhel8@sha256:fbd74802479830111e35763fea31b88da573084ad4abb427d59d766612c023b9_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-azure-cluster-api-controllers-rhel8@sha256:d085d1bf9d4a6bdae5bdaa1f4a763b5920b3e33ea934b6d1f517d08b9227e69f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-azure-disk-csi-driver-rhel8-operator@sha256:f6e4075c3c79257c2bfc92505478ef6950f2050dce21315024e95a6519065d97_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-azure-disk-csi-driver-rhel8@sha256:27cce691de1d1381b562bdb6b766869ad75edacfc05f361646e66796cea06313_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:6e35ce11cabf52a803c7cfd6d2f330a8ee2ba6d9459322cc3c3abf6b4811a57c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-azure-file-csi-driver-rhel8@sha256:25ce6b1769053a3e4e25be76977512192c26ceddbab24436f9fe7a30e866913c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-baremetal-installer-rhel8@sha256:a8a9b3fc602cd6fc44ce88479c5cbd7412b819a1253a70beec72c77f9e7ce83d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • +164 more not shown

✅ Remediation

For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/release_notes You may download the oc tool and use it to inspect release image metadata for x86_64 architecture. The image digest may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha value for the release is as follows: (For x86_64 architecture) The image digest is sha256:2f46021d7977a7211e043834bda0a0fd728e04cdc7c7b657aa1f51ee7a1fbf34 All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html-single/updating_clusters/index#updating-cluster-within-minor. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Operator can configure BMO role-based access control (RBAC) to be namespace scoped instead of cluster scoped to prevent BMO from accessing Secrets from other namespaces, or use the `WATCH_NAMESPACE` configuration option to limit BMO to a single namespace. Workaround: Red Hat Product Security does not have a recommended mitigation at this time.

🔗 References (12)