Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2025:1677 - Bug Fix Advisory
Issued:
2025-02-19
Updated:
2025-02-19

RHBA-2025:1677 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated RHEL-9 based Middleware Containers container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-9 based Middleware Containers container images are now available

Description

The RHEL-9 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2025:1303 (see References)

Users of RHEL-9 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The RHEL-9 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • Red Hat JBoss Middleware 1 x86_64

Fixes

  • BZ - 1850004 - CVE-2020-11023 jquery: Untrusted code execution via <option> tag in HTML passed to DOM manipulation methods

CVEs

  • CVE-2020-11023
  • CVE-2024-12085

References

  • https://access.redhat.com/errata/RHSA-2025:1303
  • https://access.redhat.com/containers

aarch64

amq-streams/bridge-rhel9@sha256:ac1336ee17a5de1f47dc797dc231944a377f07bceaaa36b72e97a8cb8cf26566
amq-streams/drain-cleaner-rhel9@sha256:4ba795d878bbed3655f131d784feddbc4286f542d109898dcda1ab15a6570131
amq-streams/kafka-37-rhel9@sha256:6ccbfb8082be1d57186af7e30981b410a637df2bb0372c55732a940253ae7aea
amq-streams/kafka-38-rhel9@sha256:084e154be38a4e18c689b1af8da7ef0c1415422ca0ab227dcd29f946ed8fd530
amq-streams/maven-builder-rhel9@sha256:c2317772dc65c984622b60f06b8477c1de55bd45283303578939443693820c87
amq-streams/strimzi-rhel9-operator@sha256:1400720d1ade23b98d3301830e63e57c126f766bb6d96eb9bfcf410ff2962718

ppc64le

amq-streams/bridge-rhel9@sha256:6f1886552230e5c535869133ea3090a8ae63910fa7ba8fdf0a22334b101e3c77
amq-streams/drain-cleaner-rhel9@sha256:963eb2439265e967cf60d88c443a65686c92b2b9805dd57ca459550941e1a0d5
amq-streams/kafka-37-rhel9@sha256:d04d9ba038dc1e5b9d6f8564a8a96f9169a8c40272df89d08cbd896457be3493
amq-streams/kafka-38-rhel9@sha256:0123792de465bb14a846b087f560d5b4737c04e90e384f6100ccd5b9c60350f5
amq-streams/maven-builder-rhel9@sha256:ac5b1ddf502179338aa56a38f30555ac4743286d85b5b885d735a782ebff7cc4
amq-streams/strimzi-rhel9-operator@sha256:5bf306a9f9c9c059e07f5ba2f2ad5a8d4d90ee4f1c60570df6c3afb000bbc6f9

s390x

amq-streams/bridge-rhel9@sha256:251380a634797ceacabc77f8a2bf3c564ff9e986595f099b8438eb005c8e3542
amq-streams/drain-cleaner-rhel9@sha256:350baabdb255d3b39722234a7c21a6203555472eb508249ab26332c0318508c4
amq-streams/kafka-37-rhel9@sha256:ae7876ab76a3cd0555cb5873fd85b43e243e62c55be9c77ae1dc163deff16419
amq-streams/kafka-38-rhel9@sha256:9f8b0ef57bf810aa0a5127afbd273ed1f74f28f593c42aa1e15e355b45cbc4a1
amq-streams/maven-builder-rhel9@sha256:cb37936b78f982246a2b65cd97589566e3f2e3a0ccc680341d8e5095acee98d6
amq-streams/strimzi-rhel9-operator@sha256:56121dbd72d4152a67838e903aff8722e6519be43d772bdd451c42cd09469b12

x86_64

amq-streams/bridge-rhel9@sha256:39472de32de6e3bfcd5f84cbcbdba7c024ed654ff548a2b6ca73e86307ae576e
amq-streams/console-api-rhel9@sha256:ca48acfdaeef212ecf7fdef2a0934b54c21aa9fb0741025865a07897eeb1568c
amq-streams/console-rhel9-operator@sha256:ff606031a3fe6c3d0b98848a7e1e6b344b4859c9f393f4ae02157747e2000f46
amq-streams/drain-cleaner-rhel9@sha256:0dd20d9d91b1b392bc1858698d67dc3c6b0ceec980cf38798a373186648eb648
amq-streams/kafka-37-rhel9@sha256:5c5431895061ca87d1cf52f2e5f2ef788747bef6a8eb541119afa47bc029883c
amq-streams/kafka-38-rhel9@sha256:d72b359ded1c8246e5403eaf9ddb3fe006c3562ca0490043f26b1ff09f80a42a
amq-streams/maven-builder-rhel9@sha256:a2887376994e964fb77d120d401fb7348099b3ffd61bbaecbbe1f46980516810
amq-streams/proxy-rhel9@sha256:b5c124f3188d629d7ea296c556548a6b166a010412b2d4e34ce523806658ba10
amq-streams/strimzi-rhel9-operator@sha256:07b2537d20580b2844c359839c256b5a51c848519ef8d287231d2a8bafb0f173

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility