Red Hat Security Advisory: RHODF-4.16-RHEL-9 security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2024-11831 — npm-serialize-javascript: Cross-site Scripting (XSS) in serialize-javascript CVE-2024-21536 — http-proxy-middleware: Denial of Service CVE-2024-29041 — express: cause malformed URLs to be evaluated CVE-2024-39249 — nodejs-async: Regular expression denial of service while parsing function in autoinject CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2024-45590 — body-parser: Denial of Service Vulnerability in body-parser CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing
🎯 Affected products99
- RHODF 4.16 for RHEL 9
- odf4/cephcsi-rhel9@sha256:8df6be202d7352da9fe45510e26a1fa17ee29b43851bb34f92a36d550145d1c8_s390x as a component of RHODF 4.16 for RHEL 9
- odf4/cephcsi-rhel9@sha256:9e722e6ef66d768ad25c4029a6f4796b3035a8e0bcab1eea3b0b9e3e0ac80a2c_ppc64le as a component of RHODF 4.16 for RHEL 9
- odf4/cephcsi-rhel9@sha256:b569f1f1cc542522fad6a9664ffe83135e0fac221da2db858a1e1b3dafac2a78_amd64 as a component of RHODF 4.16 for RHEL 9
- odf4/mcg-core-rhel9@sha256:13f94d78bbea30a1e87a3b71f167272268f88ec6cadd46baf0d41b6c78001207_ppc64le as a component of RHODF 4.16 for RHEL 9
- odf4/mcg-core-rhel9@sha256:266dcc4332512803feb0c2841bd447d5730512d5cd533814a55c7a73fdbbe92f_amd64 as a component of RHODF 4.16 for RHEL 9
- odf4/mcg-core-rhel9@sha256:88b3cbebf2d0d9959c9485e3bd92e8d20f5d51781b3e5e3604695d24e3df5ba5_arm64 as a component of RHODF 4.16 for RHEL 9
- odf4/mcg-core-rhel9@sha256:8e3e4d47fce84f50a8bc3a6564e588ffce84082c32026ab16e300cb4c9179f34_s390x as a component of RHODF 4.16 for RHEL 9
- odf4/mcg-operator-bundle@sha256:0995b3e355f37e1e1ddb7a81afea0a2e1d4b1dcddb8fda460694af1f54b2b852_amd64 as a component of RHODF 4.16 for RHEL 9
- odf4/mcg-operator-bundle@sha256:2271d7696060f1308cddc9f0b39484a3c896ceae0934a22a4967e4e550c6411a_ppc64le as a component of RHODF 4.16 for RHEL 9
- odf4/mcg-operator-bundle@sha256:ee6ebb4c88c990561f36695a0446d2a5bbed74f37a8bb641ec05dce0c7ae4907_s390x as a component of RHODF 4.16 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:092bd757a65a2932ec92a31e745c21125e4fbda1058e75e8f53e35bd757182a7_ppc64le as a component of RHODF 4.16 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:7139e479209a6a4ab60bd398220a48ca78a6cdeabc09619371fb80bba2beeba3_arm64 as a component of RHODF 4.16 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:7d0d36581b0f43e6c4611165cc7ab6ecc401971d50aa0d7ffd43ce7314c1aec4_s390x as a component of RHODF 4.16 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:d95d17587043a5980a4a9e2c40474238b17270b48cd28d9286abf37e8dba5229_amd64 as a component of RHODF 4.16 for RHEL 9
- odf4/ocs-client-console-rhel9@sha256:56e8b7e50e7f4e018cbfd59710ecd4283e8faa1c18d83f8acd40ec0821f540c6_ppc64le as a component of RHODF 4.16 for RHEL 9
- odf4/ocs-client-console-rhel9@sha256:eddd4bf5d536fad6764c7daf8b36709630566a916e3c9a9c38cb195037e13f36_amd64 as a component of RHODF 4.16 for RHEL 9
- odf4/ocs-client-console-rhel9@sha256:faace26bf5dcab6de85a350b65dc13529b6b8ea1e4efe54a4f1cd0cb94f72a12_s390x as a component of RHODF 4.16 for RHEL 9
- odf4/ocs-client-operator-bundle@sha256:02275650f8f2a4432f74ce61d2ad77aef628a49e15a5ba968862583875356c5b_s390x as a component of RHODF 4.16 for RHEL 9
- odf4/ocs-client-operator-bundle@sha256:1f39071fe02977accce7c0ef31b71f6e337dbb6b7f918ca7f73c34dd2c1197de_ppc64le as a component of RHODF 4.16 for RHEL 9
- odf4/ocs-client-operator-bundle@sha256:8ca8073d40aa0d9257094baf33dfa16e56600556259d91306d6d6d7727bcdebc_amd64 as a component of RHODF 4.16 for RHEL 9
- odf4/ocs-client-rhel9-operator@sha256:0a19077800fec1f56d21b7db0d71da69f0c2e736be6428c854563288780f76ca_amd64 as a component of RHODF 4.16 for RHEL 9
- odf4/ocs-client-rhel9-operator@sha256:3062c425ca8380884d424b4d96ca08414a9369337f3056c890b197dcca313be4_s390x as a component of RHODF 4.16 for RHEL 9
- odf4/ocs-client-rhel9-operator@sha256:63b44fd5c9a991e008ce2af1745d5eb280252874a50cb87254bb599a28e0db78_arm64 as a component of RHODF 4.16 for RHEL 9
- odf4/ocs-client-rhel9-operator@sha256:ef0121ba44fc3e770156cb122d13f3ca2165ef6578995814f6053752eacf0ab4_ppc64le as a component of RHODF 4.16 for RHEL 9
- odf4/ocs-metrics-exporter-rhel9@sha256:9ab03e07b64cdd003fce3842d5a3bef77c8fa0b0b7b331d6630549ee14d2be22_amd64 as a component of RHODF 4.16 for RHEL 9
- odf4/ocs-metrics-exporter-rhel9@sha256:9f944006b8fd489a75ea48598266605be7931feba94346472c030a3842a56cdb_s390x as a component of RHODF 4.16 for RHEL 9
- odf4/ocs-metrics-exporter-rhel9@sha256:cb63f2994222ad8736a6f4fd757fb683162ab3c16f59d9a17253b01dc940650e_ppc64le as a component of RHODF 4.16 for RHEL 9
- odf4/ocs-operator-bundle@sha256:0190226401fdd645ab2faf41da6b3d3484d73446116cfce28b4c4ccd7f9535a2_ppc64le as a component of RHODF 4.16 for RHEL 9
- odf4/ocs-operator-bundle@sha256:83e63a6cfbcb9b24fd0d7ac47d436801d9488ca2ada18e08fd6534f9d5f5bf14_s390x as a component of RHODF 4.16 for RHEL 9
- +69 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat Product Security does not have any mitigation recommendations at this time. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Red Hat Product Security does not have a recommended mitigation at this time.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2025:8479
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2290901
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2295035
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2311171
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2312579
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2319884
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2333122
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2354195
- externalhttps://issues.redhat.com/browse/DFBUGS-1702
- externalhttps://issues.redhat.com/browse/DFBUGS-2603
- externalhttps://issues.redhat.com/browse/DFBUGS-714
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_8479.json