Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2024:9862 - Bug Fix Advisory
Issued:
2024-11-18
Updated:
2024-11-18

RHBA-2024:9862 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated RHEL-8 based Middleware Containers container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-8 based Middleware Containers container images are now available

Description

The RHEL-8 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2024:9502 (see References)

Users of RHEL-8 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The RHEL-8 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • Red Hat OpenShift Container Platform 4.12 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.11 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.10 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.10 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.10 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.10 aarch64

Fixes

  • BZ - 2321987 - CVE-2024-50602 libexpat: expat: DoS via XML_ResumeParser

CVEs

  • CVE-2019-12900
  • CVE-2024-50602

References

  • https://access.redhat.com/errata/RHSA-2024:9502
  • https://access.redhat.com/containers

aarch64

ubi8/openjdk-11@sha256:ebce91afbb5d28195dbf36017a408b3c4d81f2cb13a2717f89e409d5ff3e9cb7
ubi8/openjdk-11-runtime@sha256:3d037cf2598739df10fa0d94888517aad29788ce9577036d70ed5e7f8491783d
ubi8/openjdk-17@sha256:ed52121d5bd753a0da46b8cd642b5eabf006302d448939ec18f1fa1c2ea38508
ubi8/openjdk-17-runtime@sha256:14f4140a7d9269f91e782ac50211310c2f93f1611691f0000a034f96d3e4760d
ubi8/openjdk-21@sha256:9174b6d063efc96cd253b69e5fddc09da4630f6ba6e3411b0996b0349caab591
ubi8/openjdk-21-runtime@sha256:fa3fb7e01614b12d567c63de8a9cc27dfdc7ba38032f887ec42b575ef1caf3ee
ubi8/openjdk-8@sha256:dbb0be97e069c723a7eb356c8475858c01d8f5061f687a3a471eb247b5f813f4
ubi8/openjdk-8-runtime@sha256:8aa0aa1dd1c153499c8e7c67f335d9e6e5d38ac424f58bb4155cb388fd73294a

ppc64le

ubi8/openjdk-11@sha256:aff928e1a41b5fa16fae67517f8cb1ff2798a351c06b553e0662a1d38abaeab9
ubi8/openjdk-11-runtime@sha256:1176bd79daae621f85733a49a3dee8ff3f08483bda1d809e5e6456a20e542c71
ubi8/openjdk-17@sha256:0ab0e78eff2245b6905c9accf4db8297880cfb389ab91a31845d2eb05be2ed1b
ubi8/openjdk-17-runtime@sha256:09ae990ffcf60b148bf182897bc59b1347734d31efb4a2ee46e8ee75f5052432
ubi8/openjdk-21@sha256:79509376110c7a93de51f3281c16aad7671299b6e9ebce43edfa226c0e5e5813
ubi8/openjdk-21-runtime@sha256:d5af1d8fe96029cf7842defe686455f40c99c6dac275e98ed332a7856d79bfa5
ubi8/openjdk-8@sha256:f53f8b33e572893d31d46c0a32b0fbdd0fbbea2f3c9c2cba5fc184b628224735
ubi8/openjdk-8-runtime@sha256:4f7bfcc1f1ddd448b1ce8b7463da435e185838ead337ef98c8d1c45f1d59c071

s390x

ubi8/openjdk-11@sha256:f1eabdcd61ffc8aa2aef5249184e615a65aa146a09283c88f39868b41fdd1411
ubi8/openjdk-11-runtime@sha256:163ff1c25d4581b3a853c73501ed7dc6eb1d07a555a6badf30017a275d419b4d
ubi8/openjdk-17@sha256:d94309f889c650c921d9ce4c3a28e2ef77b79e9fd0c60177b7cab602f07e06ff
ubi8/openjdk-17-runtime@sha256:3f88694f685f8a02b0dfb4c6958f50c5904d8d72624b200c3f1bc2337033c010
ubi8/openjdk-21@sha256:adf8b86922f4182b7520a55294f87385c573aea5722eafd97856064ae4347e2e
ubi8/openjdk-21-runtime@sha256:7bb597a2b36fbb8a07fb56b99371bbe0696f5bc55722e2bc13d95c085070dd2d
ubi8/openjdk-8@sha256:bf33b91b05a2358fa74920a46b27e8b9bd1131130e05953ac4c0ff8a6c072f63
ubi8/openjdk-8-runtime@sha256:d3d350cba8ecd63d8fb99eed75395edd7b9c25c4d1756841606850366b8473e7

x86_64

ubi8/openjdk-11@sha256:721ceb1acba750f1d5a64edafb93afd30b9ae0f3f7d062b717db4b711ff8fe09
ubi8/openjdk-11-runtime@sha256:e345065da7b4d76cb2a8739b4d9da45cdbdbd34a7fdb12c02f422208c1a521e2
ubi8/openjdk-17@sha256:6a4f98b98a84ec7b774a0462091724c62c0a1ee7d24923822ed8450bea0ce8b1
ubi8/openjdk-17-runtime@sha256:c7f73b6a2aa4d17bdae6eccbb5262564e7242585f62f10da14351cf3df7d66a5
ubi8/openjdk-21@sha256:0a2aa3806ab0c7b17f840144b7ece749e899ee97f2c617ba23acf4dd28a5a705
ubi8/openjdk-21-runtime@sha256:e950006b6f1152184989b9a98e306afe026575754474c5192678a56fd38c5e21
ubi8/openjdk-8@sha256:81c0b29ddd38363a7af44e64b3880a40c0ac04fc505ef1d672e716aa8e215ae7
ubi8/openjdk-8-runtime@sha256:abef9aa26232758bee6177fcb9b16455114ee4b99e2a19774d18f8a9b441111d

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility