Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:3609 - Security Advisory
Issued:
2023-06-14
Updated:
2023-06-14

RHSA-2023:3609 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: Red Hat OpenShift Data Foundation 4.12.4 security and Bug Fix update

Type/Severity

Security Advisory: Moderate

Topic

Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.12.4 on Red Hat Enterprise Linux 8 from Red Hat Container Registry.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3-compatible API.

Security Fix(es):

  • kube-apiserver: Aggregated API server can cause clients to be redirected (SSRF) (CVE-2022-3172)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug fixes:

  • Previously, when a sub-directory was created, it would always use its parent’s non-projected `gid`/`uid` metadata to set up its own `gid`/`uid` metadata. If the journal logs were not flushed, it would always retrieve the old `gid`/`uid` metadata.

With this fix, sub-directory uses the projected `gid`/`uid` metadata and as a result, the sub-directories inherit the correct `gid`/`uid` metadata from its parent. (BZ#2182943)

  • Previously, stale RADOS block device (RBD) images were left in the cluster as there was some trouble deleting the the RBD image due to "numerical result is out of range" error. With this fix, the number of trash entries list is increased in go-ceph. So, stale RBD images are not found in the Ceph cluster. (BZ#2195989)
  • Previously, Multicloud Object Gateway (MCG) Key Management Service (KMS) encryption was enabled even when the clusterwide encryption was not enabled and only with the KMS encryption enabled. This was because MCG encryption was set to enable when one of these conditions was true:
  • storagecluster.Spec.Encryption.Enable
  • storagecluster.Spec.Encryption.ClusterWide
  • storagecluster.Spec.Encryption.KeyManagementService.Enable.

With this fix, MCG encryption is enabled only when the storagecluster spec has KMS enabled and any one of the following conditions is true:

  • Encryption.Enabled OR
  • Encryption.ClusterWide is true OR
  • MCG is in Standalone mode

As a result, MCG is encrypted appropriately. (BZ#2192596)

All users of Red Hat OpenShift Data Foundation are advised to upgrade to
these updated images, which provide these bug fixes.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Data Foundation 4 for RHEL 8 x86_64
  • Red Hat OpenShift Data Foundation for IBM Power, little endian 4 for RHEL 8 ppc64le
  • Red Hat OpenShift Data Foundation for IBM Z and LinuxONE 4 for RHEL 8 s390x

Fixes

  • BZ - 2127804 - CVE-2022-3172 kube-apiserver: Aggregated API server can cause clients to be redirected (SSRF)
  • BZ - 2182943 - [GSS] [Tracker for Ceph https://bugzilla.redhat.com/show_bug.cgi?id=2189936] FSGroup is not correctly set on subPath volume for CephFS CSI
  • BZ - 2188331 - [IBM Z ] DR operator is not available in the Operator Hub
  • BZ - 2192596 - [Backport-4.12.z][KMS][VAULT] Storage cluster remains in 'Progressing' state during deployment with storage class encryption, despite all pods being up and running.
  • BZ - 2195989 - timeout during waiting for condition. "error preparing volumesnapshots"
  • BZ - 2208477 - Update to RHCS 5.3z3 Ceph container image at ODF-4.12.4

CVEs

  • CVE-2022-2795
  • CVE-2022-3172
  • CVE-2022-36227
  • CVE-2022-40023
  • CVE-2023-2491
  • CVE-2023-27535

References

  • https://access.redhat.com/security/updates/classification/#moderate

ppc64le

odf4/cephcsi-rhel8@sha256:7fe149cc0c3c6dfee962ce78daed94e34af663cbfc65c8c95fea3039d22bcc1a
odf4/mcg-core-rhel8@sha256:de66c0fa3487b4210cfe9f13daaa94110b601e736152afea3820a2fbc66aac2d
odf4/mcg-operator-bundle@sha256:df22542a108249f8f87d9a35c705b683399b62f94d39bdd81c1e87585e90d452
odf4/mcg-rhel8-operator@sha256:1c2286a69dd01a9bae529264a6859c1d75537502ce98b654bd53b4e34c22f642
odf4/ocs-client-operator-bundle@sha256:d48c37264d2b8d5842172cd8bd0e404d34c366bfe8ba7fcbd000b18762841d52
odf4/ocs-client-rhel8-operator@sha256:29b4517d2e0faddf742c87e5ca759bfbe436bd2e217d4fb79360f56fac3e329a
odf4/ocs-metrics-exporter-rhel8@sha256:7bbfa727bfbe5037967b34e6c3d0711f976cbf9085a4bf3b23409744d0518927
odf4/ocs-must-gather-rhel8@sha256:aceea0a5b2f1165b21c9215acb76f6e1fd88f0b41007497b33baa27cb4e63d82
odf4/ocs-operator-bundle@sha256:b6027a36b6f8fa5488caefb5a2bc29508d81e3b528a61ec81bf48af6002d6d18
odf4/ocs-rhel8-operator@sha256:9b3ebcfb057fbb958dcf2ea58de82312387cc21a28e7cc07bb797f564fc48621
odf4/odf-console-rhel8@sha256:a25689063daf0c69c654bd696b2e11978e583bab9efd857babc4ef94819cf3ae
odf4/odf-csi-addons-operator-bundle@sha256:376f5974f8657fe3aa85c4c0ba1931372c5cb2351e44f9d02f2222a167c2ced6
odf4/odf-csi-addons-rhel8-operator@sha256:28966dfefd3ba94843339f5edde9a2eba9533ff58d32a1898b4d6745278be579
odf4/odf-csi-addons-sidecar-rhel8@sha256:ae1b7e55dee6b93ef6fdacd3efd4965e51457efa4629601272aee05f5a1ead11
odf4/odf-multicluster-console-rhel8@sha256:84a28f1150151960b097432b99ab2fa6c34716441a8b9dd32aac4823c8f3e292
odf4/odf-multicluster-operator-bundle@sha256:a10a289c83d605995b2a9328464d884591831e5ef17de27f27ee5bd56efe3c08
odf4/odf-multicluster-rhel8-operator@sha256:209291f80b125bfa0b48efe143d003ee219cde8924ac46238e2581f2a7240444
odf4/odf-operator-bundle@sha256:e57f89fd338b4cf393f4cde1dd0f37c7fb51efc6fc2193d9e701781d646dd94f
odf4/odf-rhel8-operator@sha256:4f4819bbd2fd4e287f6d46d7f3a7a9e8428153ee879c40edd9f81f481ebf8211
odf4/odr-cluster-operator-bundle@sha256:24d584076d77d54ce62c8885ec5a631b5dcf090f78761e6ae3452f9aa277047b
odf4/odr-hub-operator-bundle@sha256:54d03a77d358dd51a4bc914b0e8a36be5b4acfb37c2fe9f6a9125839adc49a6d
odf4/odr-rhel8-operator@sha256:ec1f7ef20117ed60247ce479aed3308d8b29d69f454f0cf363c3847559275d0a
odf4/rook-ceph-rhel8-operator@sha256:445a7af195354c94303a357eea076e8b9f99323f3d08a156ed51c9bbece7964d

s390x

odf4/cephcsi-rhel8@sha256:8b20ec2847f20acb0290cd6c48554440ee0c76c74087124a1be42074db7046da
odf4/mcg-core-rhel8@sha256:3490758a3201514f18d36650ad0880f74337e7b982162c8853a9ef1399d45c83
odf4/mcg-operator-bundle@sha256:321acbfdd6b022f2439c1c8fa8772c79d2ded0f2a56fbebc18be01b30e9fd856
odf4/mcg-rhel8-operator@sha256:f052756c97e9a63fab1129fa08f63ce164e15c94bf66e1c851360b6579b2d5f8
odf4/ocs-client-operator-bundle@sha256:015e1f94642f3a738f568f3a87f847ce8783ffb25b1f59e5d660400d1a19eac9
odf4/ocs-client-rhel8-operator@sha256:39ee3ed5ac9c072577f9737236d03d92d1a3f3ec16e88aa4f9bc778a18af5fda
odf4/ocs-metrics-exporter-rhel8@sha256:5ddf68e048aa72f926887a37bbefd4ed7418851c5b1c8dbb7c46670839e057f2
odf4/ocs-must-gather-rhel8@sha256:2e720a33fb5fd22b75d82d63d815510182f5420ede58b2834b66389964923e1d
odf4/ocs-operator-bundle@sha256:b76aa649607ee1b0b193196303501501abcd0a0c54d8be05b3d5a596a20277ff
odf4/ocs-rhel8-operator@sha256:dc27ba69e6d75ee3e538d3d75df40504dc3cc2cdb45620faf0c7423466b8cfa8
odf4/odf-console-rhel8@sha256:4e8f469fc5498fc113ca0656b80c6a53861e14a3274c04a35eea9d31a9c07956
odf4/odf-csi-addons-operator-bundle@sha256:b5e77e3dce399cc9c3e9dd807a345e37ec0b01219b133b3e3677e9a3114f4553
odf4/odf-csi-addons-rhel8-operator@sha256:2fe2851dd6880bb145823dc9f041bd6dafa6c8566f02775a12eed452a748f528
odf4/odf-csi-addons-sidecar-rhel8@sha256:2c0085e0efaffcfef4aace1a0551ee8799cb3770e5df94d97fffc0e0943c273a
odf4/odf-multicluster-console-rhel8@sha256:c4987a159b452700505d42ff93bde0fbfed5671a77d135971fc10b728c777603
odf4/odf-multicluster-operator-bundle@sha256:964d039eaade59e0a32f716475c24e36509c678116a7f8058f96ebaa4bed04ba
odf4/odf-multicluster-rhel8-operator@sha256:5b76f6a732ff9dc96820fcb9ff56ac30575ae7e05281a64035f9ccd2d154534c
odf4/odf-operator-bundle@sha256:4a9f30e42690113ef4156092834687f6a92fbe6c349f6f6a46d0266433a73d87
odf4/odf-rhel8-operator@sha256:bd06e4060a737f0def3a01aa81059c95cbe970b542e3748b81dc4a52d153e93f
odf4/odr-cluster-operator-bundle@sha256:1e9c89e7e05cde772591dec21007be1939d34d90872346fec7f10803c90b3ac2
odf4/odr-hub-operator-bundle@sha256:e0ca1e7a67e438c872bd0a4028dd015caf5cad28fc807185d703814df9ddbf63
odf4/odr-rhel8-operator@sha256:2d8e563f015605c44b3d8cf66e1ccf33bb04402760d63777d86157fadac46e97
odf4/rook-ceph-rhel8-operator@sha256:4a4271bd6e3e4076e8e55a33607975335098ce368dba2b758e64874081d48368

x86_64

odf4/cephcsi-rhel8@sha256:a424234c60d59de61f6479371c4a33caca808527dfca6f511fbbda1eacb091bb
odf4/mcg-core-rhel8@sha256:f75c564db068d34fef941bd88a00af6ad597ae4a725f693a1220551cd65912e9
odf4/mcg-operator-bundle@sha256:1294a3c6e271236be2b303ae85e61f7704b7f5e14014bed55e20db534bb1535e
odf4/mcg-rhel8-operator@sha256:8d622b214bee71eb8f5bc1636b3cc6d27473e5b7dea90b2f0c192f83807a7957
odf4/ocs-client-operator-bundle@sha256:4fcb1eb6a10d0d1bbc809e8469acdf186ef363301b1c45a1767fee6857d0bae5
odf4/ocs-client-rhel8-operator@sha256:478ac5320a82780b6658eb0502dae4df9cb59633a6e2971ac1e695380f771e76
odf4/ocs-metrics-exporter-rhel8@sha256:5ea7b45de1219d1406fea05a99b5bc7a4ea3a96feaa2a303817d886bef55a224
odf4/ocs-must-gather-rhel8@sha256:4253057ab67e221ecfc87beb4b6f8acbbc602f0cc1313b7dd66bc0584d74d3e2
odf4/ocs-operator-bundle@sha256:8982289d5dd7e54a0dc03c6c6839da78dcccca05751f95a371971a202bf35b2d
odf4/ocs-rhel8-operator@sha256:2ffb7e1609434456310e89867681013d42894478bed0ff646425691affbcecd9
odf4/odf-console-rhel8@sha256:36845a594380ad9dd77aa4f9019fce062791d8d2baacdd41b799b05b2910bbed
odf4/odf-csi-addons-operator-bundle@sha256:790a1089a310079b8d13d76021068280a065dab75925e7d63203f063ced3b6b8
odf4/odf-csi-addons-rhel8-operator@sha256:7b866f1cc151de4d46e69aa1950ee6af49ed7a24f03d0b49c1a134991048d782
odf4/odf-csi-addons-sidecar-rhel8@sha256:590f2e49fbc2610a5e8967f798b5083c4a9494ee043305ab6d8ccddc231592c5
odf4/odf-multicluster-console-rhel8@sha256:2bd076e2090fe387687d777acb559128b1ddc9c8a39a8954339e2ffd703b416d
odf4/odf-multicluster-operator-bundle@sha256:e31d59ce2d1f0b143dc4fd829a69526ff0f78b253d6300b7b6ab39a790f90ed3
odf4/odf-multicluster-rhel8-operator@sha256:9d959c2172b1f9937bf21101e7ebd1aa5febbfe4c18b7c3a90eaa085b7e18ac3
odf4/odf-operator-bundle@sha256:5ccc9c304ce9aa903bafcbfc6013f6608eb1311724a89da4fb9b674d713c4c6c
odf4/odf-rhel8-operator@sha256:f3d12e90b7a2bb44e15da2b9082afc361c1e1555e8c2bd24a022cd00ea755838
odf4/odr-cluster-operator-bundle@sha256:e812a2a4e09dd060169b683017cb61e42a3c2487eec162e044e4cf755698b01d
odf4/odr-hub-operator-bundle@sha256:9b6647cef3ca8f9c368fbe2a62152450a075405f430768f08c713008abd9a6cd
odf4/odr-rhel8-operator@sha256:b2ba54ee096b54f348e539061132fedb2dc274ae62105d7e4f769578c3b68ddb
odf4/rook-ceph-rhel8-operator@sha256:cb5c9190f28e1fff2d5c05011f962e9be0d6dbfdac43cd070f44078452a2dd74

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility