Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.14.18 Bug Fix Update
🔗 CVE IDs covered (10)
📋 Description
CVE-2024-11831 — npm-serialize-javascript: Cross-site Scripting (XSS) in serialize-javascript CVE-2024-21536 — http-proxy-middleware: Denial of Service CVE-2024-21538 — cross-spawn: regular expression denial of service CVE-2024-29041 — express: cause malformed URLs to be evaluated CVE-2024-29180 — webpack-dev-middleware: lack of URL validation may lead to file leak CVE-2024-37890 — nodejs-ws: denial of service when handling a request with many HTTP headers CVE-2024-39249 — nodejs-async: Regular expression denial of service while parsing function in autoinject CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html CVE-2024-45590 — body-parser: Denial of Service Vulnerability in body-parser CVE-2024-48910 — dompurify: DOMPurify vulnerable to tampering by prototype pollution
🎯 Affected products90
- RHODF 4.14 for RHEL 9
- odf4/cephcsi-rhel9@sha256:b9f6fb8c6e5a919ff7b1aead2e220db45e010d285aa3134a060865f98dc8ff4d_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/cephcsi-rhel9@sha256:bcb328a210baf1ccff7c7373d8cb80f951c8902e6f1b25f543e248923ff11bf1_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/cephcsi-rhel9@sha256:e741ce258ceffff394b453da219439e788a7c60277569d2145667b0f1a27cefc_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-cli-rhel9@sha256:590d6f1c2d28e9750fb2bffec2dd60d943e6f3de5e3bf801917055c9053d55cb_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-cli-rhel9@sha256:7d462a0cb3bdaf33e7f1d68d2cc2c3b65937e97687a36a6c5f0c21002cba339b_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-cli-rhel9@sha256:dae4433fdd1054a34badc70ce5db933c936f9e270cbc93a03a408beac0731ee6_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-cli-rhel9@sha256:eb314a5553470a5a881e277b1962f7219ee0968d4319e55cb7427258a73e3a25_arm64 as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-core-rhel9@sha256:58883135500207c3f149882421ab3d7c14ee8c934c107d563d1ac51d9dad2188_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-core-rhel9@sha256:657f10ecba6e3e484483cc2bdfc7a7cda10f1fab85360c40bb9ef4f1929c4cf2_arm64 as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-core-rhel9@sha256:7600a8dcc458fdf3b029667c361b3babf0a42a8a8194bb3c90216abb0d37e617_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-core-rhel9@sha256:88643caf11bdef38053b7972a376035591e4ecfe03ed7a52b618211b1e1c3e6f_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-operator-bundle@sha256:1eef1245af12bd0049fa88de90549ce23e6098f08cd8273fcbe1552ce5841f98_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-operator-bundle@sha256:b70c0ff1f0c5c44f62d77927a3cb4fb22aa7924ba802b09d2f8ef66258522462_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-operator-bundle@sha256:c3143fd1da13f7470f07df869630c4de1cd3c390676e096b2cc61df1ce0b3c20_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:1b220688bcbade808c2fc05d9160547b21fc34672ff653cb16360d485c721669_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:5e932572c6cc187fe1791abe29b71d5fdeb2c0e7a81ed90b46cb3d358aa25e71_arm64 as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:b93a4133ab036f4a44471e9c8ac0274e9651177d72ae3fdf1d73bbacb31b2e63_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:dd9c5f35896ff7a7aa622510f969343e3d8c582659753dc6f8aa40bf21ce258f_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-console-rhel9@sha256:0db1703649e40cdb563f269ccfb0e80724f13034b21e9c5482ea22a82af61b85_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-console-rhel9@sha256:3739dbc4cfe67226e97b803279f65a017031d60b24a944d031232ce579a2501b_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-console-rhel9@sha256:86a2494cfd358f367ea250d8199d9baa2d6da7a0c6366ed03a55b0648da52c24_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-operator-bundle@sha256:5c84ed51c74952ca24757662d3c4856b90cf0a4d856b3807f0c0b57752072b97_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-operator-bundle@sha256:a32c47c452fce1a32a15880b9e5c2c561e656a26c143cc46a54368fcaa614863_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-operator-bundle@sha256:fb23e5e9463322406db0671616bad500c99d201386e38b6298165d169b32e8f1_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-rhel9-operator@sha256:30b766091deb8fca244ba8133226fcb71f06caea4601266875cb201b2c05df9d_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-rhel9-operator@sha256:a5e0d9864da87cbb2e787b51f44c9c1c4b5d73bb24aa6660e0bab25c68fa3e78_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-rhel9-operator@sha256:b9d281eb35128e5f1c96ba1383259dff9b2e60dbb27c092f27de4f2e12a8f08c_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-rhel9-operator@sha256:e8860ec492739e0eee28bdefb5934d4274ef9bc49d4d74fb9015153a39958af8_arm64 as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-metrics-exporter-rhel9@sha256:541fd697cc7cad79abd38c1ea593745d8b89153cc82137136cbfa840257d8dca_amd64 as a component of RHODF 4.14 for RHEL 9
- +60 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat Product Security does not have any mitigation recommendations at this time. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: The issue can be mitigated by reducing the maximum allowed length of the request headers using the --max-http-header-size=size or the maxHeaderSize options so that no more headers than the server.maxHeadersCount limit can be sent. The issue can be mitigated also by seting server.maxHeadersCount to 0.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2025:8551
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270863
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2290901
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2292777
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2295035
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2311171
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2312579
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2319884
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2322949
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2324550
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2333122
- externalhttps://issues.redhat.com/browse/DFBUGS-2605
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_8551.json