RHSA-2025:8544HighCVSS 8.2

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.15.14 Bug Fix Update

Published
June 4, 2025
Last Modified
August 26, 2026

🔗 CVE IDs covered (12)

📋 Description

CVE-2024-11831 — npm-serialize-javascript: Cross-site Scripting (XSS) in serialize-javascript CVE-2024-21536 — http-proxy-middleware: Denial of Service CVE-2024-21538 — cross-spawn: regular expression denial of service CVE-2024-29041 — express: cause malformed URLs to be evaluated CVE-2024-29180 — webpack-dev-middleware: lack of URL validation may lead to file leak CVE-2024-37890 — nodejs-ws: denial of service when handling a request with many HTTP headers CVE-2024-39249 — nodejs-async: Regular expression denial of service while parsing function in autoinject CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2024-45590 — body-parser: Denial of Service Vulnerability in body-parser CVE-2024-48910 — dompurify: DOMPurify vulnerable to tampering by prototype pollution CVE-2025-22868 — golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing

🎯 Affected products90

  • RHODF 4.15 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:21b8cf141ecf150fc0810a008c8e38e370ba688c3cd6f3457c3e6fc3ee52b4d6_ppc64le as a component of RHODF 4.15 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:22d3683f9aeda98b9ffc78e56e4fda94c94f2b238fdbb4571544e1389c8c780c_s390x as a component of RHODF 4.15 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:3c7347793cd8cd257f502c773f9160c9a0206b22b02cf6b38fcda0957df71195_amd64 as a component of RHODF 4.15 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:4bba4ccd15bcac9199e2dd8e303392b4fd0996a4d6b985b542a50e7d6b2969f7_amd64 as a component of RHODF 4.15 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:6dad7882970e02ae4305a5b67b2baac56010c752628a69b45758c6ce290b0221_arm64 as a component of RHODF 4.15 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:a56aca673c704e876691dd83498943f3f8db6c0253de88bb2c0bf548b0fa7d38_ppc64le as a component of RHODF 4.15 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:c8c4143f46151064487a1e412fe36686392e114e49fd1bb17f9c625fa4b97754_s390x as a component of RHODF 4.15 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:726df27ad9d432f1fa7f6c75266e6f562fe629284fe1511f94d2a4a38c6c1645_ppc64le as a component of RHODF 4.15 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:7aeae4a434a1db77c1461d904227075a3d9174cea6ebcebcb2cd6d15c6ee36ce_s390x as a component of RHODF 4.15 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:d5bc11198e1534cbd9ceab7ede95208541199dafa509aceea57ceec565be4263_amd64 as a component of RHODF 4.15 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:16ce19df455cdabaf4ea4b46d04bd5545fd48afb7461ca0a1eae93b397a93e7c_arm64 as a component of RHODF 4.15 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:51c3b61adbaa32a71ea88fe696d244cf7211d3f0f4338c04409cf034c0d3e648_s390x as a component of RHODF 4.15 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:542533139948377f7f070eefb62c1fe385a86b754f506308535790787cf1d279_amd64 as a component of RHODF 4.15 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:766a960eacb7eda308dc93bb19b8562a732dc07a6af6e444c728d215f61329d1_ppc64le as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-client-console-rhel9@sha256:1882fa5ee99205e6adccf2bb748a8f7556ce24bb0984945ff873ffa28bb8e6cc_amd64 as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-client-console-rhel9@sha256:2ddceee0eb1df73ed31f43c255ff2a0909182cc65ffb8d5b3a8c12b799353308_ppc64le as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-client-console-rhel9@sha256:991cf5cf098a76ded35e375b0d6cb18e7031ccde28b15293c0d180d66161dee9_s390x as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:86e618756adc5c11c7d6c93ac4ef98254573f33974bd40bd9437047bdaaab064_s390x as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:88ec58a7da882000b8e6588043889cc04f12cb2ddc22de9ad56beba038265446_amd64 as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:c27dd90be2061ff149347f708dee2e98a9253e9c354e987abe956ed1fe4c9506_ppc64le as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:23eaa0055fe21575f001b289b218528299be0758bbc81dc7c96ad8881e575c93_arm64 as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:4119ffdae2af4343e69647c8832ad7059f050f25586ebbaf9f4f117c711e32a4_s390x as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:5987d7027a35dc683f5f12111dc0ade483019ebf4879244746c2aef783930fa9_ppc64le as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:8a2815f90acc846be5cb989be5fac10125d820a927d21c8a26e0982d728bbe24_amd64 as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-metrics-exporter-rhel9@sha256:0b21eff1f4effc630145bb027c228d08fa46a685f87d8dae4a2f7a10b73a9950_ppc64le as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-metrics-exporter-rhel9@sha256:5a5a0aaba3369479e18693adf7cc7acb1cbb65c6dc170db882ea244aa33ed52f_s390x as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-metrics-exporter-rhel9@sha256:e1544c0104c8383b15bf274d5d308bb8b26cf3f7bab693a729f005697852276f_amd64 as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-operator-bundle@sha256:30acb6b8840fd5e433441507c00d215a9d6ed2f02a39b0891392fb9eefe375bf_s390x as a component of RHODF 4.15 for RHEL 9
  • odf4/ocs-operator-bundle@sha256:4c711bfecd9bdd055508a8ee96b3215d808a82d18e69ef221bec3a3734567751_ppc64le as a component of RHODF 4.15 for RHEL 9
  • +60 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat Product Security does not have any mitigation recommendations at this time. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: The issue can be mitigated by reducing the maximum allowed length of the request headers using the --max-http-header-size=size or the maxHeaderSize options so that no more headers than the server.maxHeadersCount limit can be sent. The issue can be mitigated also by seting server.maxHeadersCount to 0. Workaround: To mitigate this vulnerability, it is recommended to pre-validate any payloads passed to `go-jose` to check that they do not contain an excessive amount of `.` characters. Workaround: Red Hat Product Security does not have a recommended mitigation at this time.

🔗 References (17)