Red Hat Security Advisory: OpenShift Container Platform 4.20.23 security and extras update
🔗 CVE IDs covered (6)
📋 Description
CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-15284 — qs: qs: Denial of Service via improper input validation in array parsing CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-22029 — @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code
🎯 Affected products178
- Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:3f8426a334d0765c1eb1924d6a6cbf253dda2cebfc0b1cce206b8b275b42c0fd_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:76afd066ad028896c92283635f28dbd12566b40d8de159d5990cfd3d6e459f7d_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:d5a1a1a67f49401d36a8b878d373eff59a6c7543acfeec046d7fb58369ab9ca9_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:eadf36bf654b7485bb3307fdbf31b99bc3247ff877eaffa180502d6c38659d8b_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:cbd3f992576bfada0634440140672211b2ab45251a734a055ba705854607df4e_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:d3a470079fabed9427c397a6a3ac99b479c4e166b2d7309cd3d167a863506a06_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:d48f90b886ed41ab1d265e29f7eb54ede7b4afcfab9840ccf4bf2118eeb67480_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:f1fd2ea42071ce0fb251fcfa607a0f9d666f6fb1f4f2d719c7fb2e2cff9e6c6f_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:21100ce4e1debcb748fa4a11950e681d05858daa45bd58822cbc3943aea29ee5_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:3f54dbf194c3b4e7aa57325696220171ad9cf6bad9d063afd135f3caf0c15d05_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:a6d4614886b85925292d67af4a90d1c477f6f6295dbf2bb969463df22c93ebdf_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:ca7a069448d2881c1699d8fe230c43c0ee46be185deb15f9b17b211b3e03eb2c_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:30ba2a372e0e34dd0fa2733c8e38caa296f178b5fe8867f44917b159d4a7f07d_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:8ba07af9117eb0392bb40f67ccc314cb572d8500a98b558dd873393ff69d9cd0_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:eccc86cd2594da5b50991799fac8f2fc977e7b83f3c3f4ea82b788cebd6f4891_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:ffe901156f1184a6fd300104fb9ad6074ebf60ec9c97cd7f64d471bd8c6c946d_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:01e9bb5b71fd054609fa1acddf226840583a0a81c86e580d24235542f2bdffa7_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:328cc2536dfbbd7f378f012a15b3bf0efe516c6c20804a044f49ef05164bdf62_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:37a948bc89ef8a8801db9c1e669a026aa336aef5ff80ec96382c469cd1b3ec9f_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:eb9d0dc8c90d29b76d88ae0f92bee314924eaed2f229989e3f940817dd9b58ba_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9@sha256:2fb899d58b5fb8e02389f944302ddadf742cc2f43d70eac2b708f763e508d4fe_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9@sha256:9efdc4cbffa23e79f8a97c48ba139bfb6a3bf2f43d17009379036ae77d986652_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9@sha256:eb8f314d56ac188d2a4e6aa6d7f3603c292da4a26429277f4959b5ff1891c306_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9@sha256:ed258a6bf35eb4e902dd4e887cd0a11eeaaba789e113b924d3a924f150d4c15b_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:629a77765341fd6396219d2d960587e3ac14bbe329598cf62b2319a90bdb5577_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:7330fed163d93521df33c3066c42a40e796fbf721dcb34c21a2db73aa8782e2b_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:b0cd6e7f86f22e68d701fb018c6bc93e3911e2ec3e96896735d75a472b032b49_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:d5eea051cbf7b2c43eedc9157b04e6687db296f515550dc5a6c2ed8cfd12bde8_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:12a31fa39afb16f689f44eb59b63adee1aba7202a076261e93e0af6e125f5c98_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- +148 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:17469
- externalhttps://access.redhat.com/security/cve/CVE-2025-13465
- externalhttps://access.redhat.com/security/cve/CVE-2025-15284
- externalhttps://access.redhat.com/security/cve/CVE-2026-22029
- externalhttps://access.redhat.com/security/cve/CVE-2026-29063
- externalhttps://access.redhat.com/security/cve/CVE-2026-35469
- externalhttps://access.redhat.com/security/cve/CVE-2026-4800
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_17469.json