Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2024:10809 - Bug Fix Advisory
Issued:
2024-12-04
Updated:
2024-12-04

RHBA-2024:10809 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated RHEL-8 based Middleware Containers container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-8 based Middleware Containers container images are now available

Description

The RHEL-8 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2024:10779 (see References)

Users of RHEL-8 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The RHEL-8 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • Red Hat OpenShift Container Platform 4.12 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.11 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.10 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.10 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.10 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.10 aarch64

Fixes

  • BZ - 2321440 - CVE-2024-9287 python: Virtual environment (venv) activation scripts don't quote paths
  • BZ - 2325776 - CVE-2024-11168 python: Improper validation of IPv6 and IPvFuture addresses

CVEs

  • CVE-2024-9287
  • CVE-2024-11168

References

  • https://access.redhat.com/errata/RHSA-2024:10779
  • https://access.redhat.com/containers

aarch64

ubi8/openjdk-11@sha256:6357581a6f32b371f7a61e63d794a035e940cc9a1a6ce8ffb59499495e482792
ubi8/openjdk-11-runtime@sha256:ebe0cd2718c1f03c5f6507962540571caf68cf6d2cdde18afc9d4652912c4134
ubi8/openjdk-17@sha256:dbdcd5b8fff13d8535f7e80223f5c4dcbc3ead3e8bb965f820a12f7ca711f1ca
ubi8/openjdk-17-runtime@sha256:e454977aade5c63865a5cbf7e0e6514655fc78ee1e947dc33244e86932ab77f4
ubi8/openjdk-21@sha256:fd070a296d3165b2407389559ce81370919a48a50d5c49c43f1b4ab5a02228ad
ubi8/openjdk-21-runtime@sha256:b91ab1460b276e9477ccfa6e491f72924df449fa38ee1258bbdb7e46e39bf59d
ubi8/openjdk-8@sha256:3e568e4816e9cd13b4ff416fc6d5710ebe2dd5759f89ff6491794052cc88f1ff
ubi8/openjdk-8-runtime@sha256:e1be9bbdd2cc211d32f9154d26e5d3c6f1bbeb1387e9d859e6cbcc0ab9d15123

ppc64le

ubi8/openjdk-11@sha256:7658c2ba39d8f96520937006cb474c1b788f6f589bcbeea29cded53d3fb78eac
ubi8/openjdk-11-runtime@sha256:7db65ba7f4b9422338c4c16c4ed0f9705fca2d7d4fc85c20dbaa0067c95c49b6
ubi8/openjdk-17@sha256:5cecd3f2270a52573a5d06ce0c5880654923412c04b442ac0853f94809ee0d2b
ubi8/openjdk-17-runtime@sha256:a5a7b2f04c537ddfd2a4674cd3fdff471a5b16c9aede0b84d5b23b86db960c06
ubi8/openjdk-21@sha256:cbbed5d14f23d1eec3cf0590e82e950135eac393243225769dd1a04b4edb51bf
ubi8/openjdk-21-runtime@sha256:487a65b6b3eda9e3becaec7190624db1954396b9f7140608614d1763678300c7
ubi8/openjdk-8@sha256:e36998a590a4b6989e0b74436093b2e0e06cb566b56e61f79a6868db2249ae89
ubi8/openjdk-8-runtime@sha256:8fcfffaabc5777ce4b3c9a5287182d47f0ff2a8394f756c9a5805e7e2bb27c1a

s390x

ubi8/openjdk-11@sha256:b7ac899ffe61e4b40b5d2ee390163be37c83ad2f77356b68d43d29e3d52b1b28
ubi8/openjdk-11-runtime@sha256:416b750f8f56fe690ea27b573ac287de3f084f979f9b4904df7b7ba626cf41a1
ubi8/openjdk-17@sha256:d8c48d63785ae3ebb6303b86d004d1f70d8ca013b5e60f664df9f6d11940f2bb
ubi8/openjdk-17-runtime@sha256:c8bc5e489428b8ae5dfed2953664b653f6f25aaee64f69fa007c483e208e41d9
ubi8/openjdk-21@sha256:c57a05d404dce6e468e535fc82adbf88bb711ffe451f2b38a355fa4c198ce3c6
ubi8/openjdk-21-runtime@sha256:cc12053971446d67eb16bbc31870924223c0db7dfd54f51ae45033c9f6967865
ubi8/openjdk-8@sha256:7309f09973012b37e1468ba05f71b55327e5fd512b91519f3a831be55bcbc6dd
ubi8/openjdk-8-runtime@sha256:6d3c3fddab6c675165d621f71fbaa25d75a05d84b25aabf6d383675dae795e63

x86_64

ubi8/openjdk-11@sha256:084089ac53d676f315e349b3f485344c3808295544f4f5c2bde30af3987cc54d
ubi8/openjdk-11-runtime@sha256:1456cce3b6a216f2e678b4592a11671dc6dd9d0cccea5674740accd83ba404f8
ubi8/openjdk-17@sha256:292c8fef0b65796ee0d1eeb83dae22313cd1e6d6caab8ed811e6da0db51c1643
ubi8/openjdk-17-runtime@sha256:83dd981c5017ef367a3dcb5889574e9ca7c46c205ed5c2a1756bc7a921b216de
ubi8/openjdk-21@sha256:4353c17f56442c6b27541e79b8659bbd9d05b7f447357b85e89260e6d05c7bf9
ubi8/openjdk-21-runtime@sha256:dae446196a3b3974365784584ceeff5676d725273ede744bac3e2cb5a2b7f97c
ubi8/openjdk-8@sha256:1be8a474e463dda72e36ef483d46cc7eb58ce2d369f03e746e4ecd9a59588665
ubi8/openjdk-8-runtime@sha256:49b718c509fb675cfdd0f734a6ccc14e6ccca4e9bd58565bff7d7cbd6b4436d2

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility