Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:4437 - Security Advisory
Issued:
2023-08-02
Updated:
2023-08-02

RHSA-2023:4437 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: Red Hat OpenShift Data Foundation 4.13.1 security and bug fix update

Type/Severity

Security Advisory: Moderate

Topic

Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.13.1 on Red Hat Enterprise Linux 8 from Red Hat Container Registry.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3-compatible API.

Security Fix(es):

  • openshift: OCP & FIPS mode (CVE-2023-3089)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fixes:

  • Previously, an empty screen was seen for the topology view of the external mode because in external mode, the nodes are not labelled with the OCS label and hence, the topology view did not show the nodes at the first level.

With this fix, the topology view is disabled for the external mode clusters and as a result, the confusing empty screen is not displayed. (BZ#2213739)

  • Previously, in MultiCloud Object Gateway (MCG), there was a significant degradation in performance with read and write operations of small objects. The degradation was because the Remote Procedure Calls (RPC) between the MCG endpoint and the core that were required to be cached, missed the cache each time causing an RPC message between the endpoint and the core per each operation.

With this fix, the lookup in cache is fixed so that the existing data is found and not queried at each operation. (BZ#2215976)

  • Previously, there were repeated crashes of the MultiCloud Object Gateway (MCG) Operator because the operator collided with the updates to the structure when it was trying to print a debug message regarding an internal structure in the MCG Operator.

With this release, the print is fixed so that there are no collisions, thereby avoiding the repeated crashes of the MCG Operator. (BZ#2216401)

All users of Red Hat OpenShift Data Foundation are advised to upgrade to these updated images, which provide these bug fixes.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Data Foundation 4 for RHEL 9 x86_64
  • Red Hat OpenShift Data Foundation for IBM Power, little endian 4 for RHEL 9 ppc64le
  • Red Hat OpenShift Data Foundation for IBM Z and LinuxONE 4 for RHEL 9 s390x
  • Red Hat OpenShift Data Foundation for RHEL 9 ARM 4 aarch64

Fixes

  • BZ - 2212085 - CVE-2023-3089 openshift: OCP & FIPS mode
  • BZ - 2213456 - Set ??maxOpenShiftVersion to block OpenShift that didn't upgrade ODF version
  • BZ - 2213739 - Disable topology view for external mode
  • BZ - 2216401 - ]backport to 4.13.z] noobaa-operator pod shows multiple restarts
  • BZ - 2218181 - [IBM Z/MDR]: With ACM 2.8 applying DRpolicy to subscription workload fails
  • BZ - 2218316 - [DR][4.13] Pass-through CA certificates to Velero for k8s object protection to function
  • BZ - 2218487 - [MDR][Fusion] PVC remain in pending state after successful failover
  • BZ - 2224244 - [Major Incident] CVE-2023-3089 mcg-operator-container: openshift: OCP & FIPS mode [openshift-data-foundation-4]

CVEs

  • CVE-2022-46663
  • CVE-2023-0464
  • CVE-2023-0465
  • CVE-2023-0466
  • CVE-2023-1255
  • CVE-2023-2650
  • CVE-2023-3089
  • CVE-2023-24329

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://access.redhat.com/security/vulnerabilities/RHSB-2023-001

aarch64

odf4/mcg-cli-rhel9@sha256:06b551bb427c765bdc8c1152af299ec5bcf267663a93a024b036bdcd501eb42a
odf4/mcg-core-rhel9@sha256:65962b0f8f7f811977ee5c7f95755a44791bcd84c0e3db7aa886ba27317f9be8
odf4/mcg-rhel9-operator@sha256:0c83a1e2f4f5b90f274d2df5aa0c42b7383bc6bee5a074ee84ed5523f6ea3ecc
odf4/ocs-client-rhel9-operator@sha256:9766eee2586d671e1e57ebd817eaed18a97692cdbea8dd6b0297f474dc3856e2
odf4/ocs-rhel9-operator@sha256:5c84918492fb2990a8fd18de240a86184b3e325bd0b8a080cc96ea62bb7b742c
odf4/odf-csi-addons-rhel9-operator@sha256:3ec3680dd35413fbd1b69f16fc5cd6a1df68105708d3a2c6bb6b9025af01e35d
odf4/odf-csi-addons-sidecar-rhel9@sha256:5aa615a9a4e873d6aca196319f5964a6478a041c0919c13a394411792f343bfc
odf4/odf-multicluster-rhel9-operator@sha256:8ac941933937786eb1f6c44a9e99221f7de74217d320fb59581674a47557db49
odf4/odf-must-gather-rhel9@sha256:d82cfad814a48c4fd56bb7aaf8b138c10d85cec6eda38e083067d8bc75a335a3
odf4/odf-rhel9-operator@sha256:ab33554b4579d81c0eaba6656c29f10e4e7fd51ca5d7f98e1676cbabb3627ea2
odf4/odr-rhel9-operator@sha256:54a37c08869cd4bd5859d08defa64022c94768e5f289456379ee44da3e071087

ppc64le

odf4/cephcsi-rhel9@sha256:0546a7d05bf027816fe47e873527516ce2a5415eb7fc10dc6751e33d07d8f8cf
odf4/mcg-cli-rhel9@sha256:eda49c283a090a4dcdd0e16f2b655c8d36f7f9cbf5a083a0962bf0df8383a8eb
odf4/mcg-core-rhel9@sha256:c4ebd9e7a0fe8925275c7f4d6151cc0498f1dbbe722efe7ad5a6a58c17818d80
odf4/mcg-operator-bundle@sha256:d3e7fae38130f5a0bbe87b91b2b3d8a6bdc05c2b1c2d3b3b636df08c74ed6e1f
odf4/mcg-rhel9-operator@sha256:5a3ecefac41fe422901de46c356228731cc5dbedf08604083a08a1233c9dafd4
odf4/ocs-client-operator-bundle@sha256:728724d536dc501b077bafa03d9d15a512c3a192269a1e616afb8aa6072145cb
odf4/ocs-client-rhel9-operator@sha256:afc290386fd027bc91490965b2b082b3bd30a84506346c904228bc7dcf5631b4
odf4/ocs-metrics-exporter-rhel9@sha256:f01d4c6d75bc57aaf1b5556f169fab5d1501d856d45ba69cd9a5aad50001d42c
odf4/ocs-operator-bundle@sha256:80c605f090337142298db77a4d50cfd5872fbc3d790405055836dd8c781a832a
odf4/ocs-rhel9-operator@sha256:267f20c098ed886d96fc6747fda68952bf40746d2305c9d79791c61e6b3cccc0
odf4/odf-console-rhel9@sha256:932590ea650bc4a48f40901bbd7d6eec53c797fe0af5359db0f9175155921050
odf4/odf-csi-addons-operator-bundle@sha256:b34ef31ff3ee03bcdc5d39dce53ad406a67324be1a8e254a71b76347047408b1
odf4/odf-csi-addons-rhel9-operator@sha256:f0b3c81e70343ac28d295ca7e8b44c3aea9b2bd723b351b0b0981f0206f67dfa
odf4/odf-csi-addons-sidecar-rhel9@sha256:e940140afde83ce95196e251f97842da65ec4b3cb286eeead775959ec7aacda9
odf4/odf-multicluster-console-rhel9@sha256:9ae251342e701506b12e3154999dc15b8fd857ee32696139342faaa958149d72
odf4/odf-multicluster-operator-bundle@sha256:4e70aefb6e0c44d7955d0c82ea5babdf0589c959833f95e82f280bc154a72625
odf4/odf-multicluster-rhel9-operator@sha256:de6d09c3f8d270c886bc891bde84a4d9932083866893878ab69848ded8404821
odf4/odf-must-gather-rhel9@sha256:c9a06ed6762923904d62c949b469596f5c7ae969502058f7d3d8f29db1269f8e
odf4/odf-operator-bundle@sha256:c8fc2ea85fd257f59cb02b03d0639e194f3f1ded0fc18767fdc05efa7d139097
odf4/odf-rhel9-operator@sha256:08568bd98da3bc5f6070f8c576cea960839698bcb4254e5e984965b8587a05e6
odf4/odr-cluster-operator-bundle@sha256:5c355adf4937b54945ea6b48e5fa9e1b06df64b89b1bafae309c281b64fdb82f
odf4/odr-hub-operator-bundle@sha256:bba52e670ad17d7d6c24d1a8588d96ed5e34df266b749c2c2d0d6b9d2bef91af
odf4/odr-rhel9-operator@sha256:efa67b564008b882f96d4c8505430fbb711dc05bcc73ccb05180ece4a83c209f
odf4/rook-ceph-rhel9-operator@sha256:6684fc67606d16b1cd7f27a45a7eee042d6b728844a610f5d073dcabe80a8627

s390x

odf4/cephcsi-rhel9@sha256:e16ff17fbc75adc541ef551c14f9b3bdb4e8ddf193cba9e584997e3fa5215db8
odf4/mcg-cli-rhel9@sha256:55fe67c756bc266cd62ae7ee501e71c16bef92689d68f5ce77ea77cbbf6ef805
odf4/mcg-core-rhel9@sha256:aabc76e924696152927d8d064191136829ac83d77f629a6ce5e8949a720fa3aa
odf4/mcg-operator-bundle@sha256:9e552b7f9aa31c44a29c18c5217b8a2f04dd0091d4265e6ac35f09ac0ef5517e
odf4/mcg-rhel9-operator@sha256:485702326aba60670eead033aeb862550d053edaa31ffa722052fdb853a07274
odf4/ocs-client-operator-bundle@sha256:28127dcd3a21a30ccf7d545494b8d947c14f0f2ba1418f559d73f4997bdb83bd
odf4/ocs-client-rhel9-operator@sha256:b5c9f8765f50eca7f773f4c8df4e210d704c58b812f5ac9fdd68a1c0419e1faa
odf4/ocs-metrics-exporter-rhel9@sha256:77487dd8359dcec1fdbabfe8cd0f243231b9f281184526ab5494533b5a5fc9b0
odf4/ocs-operator-bundle@sha256:5918d1291ddb16449e48e3d3cb70f254fa65145a22b9ac81da31c5d6fa677354
odf4/ocs-rhel9-operator@sha256:974082227bc7e21710282fa8a33519bffbb45269baace686c2119f97785a10b0
odf4/odf-console-rhel9@sha256:9f222f8b901a0d80a84095fa29bebad475450135836ed0c4f8f94388f66e5180
odf4/odf-csi-addons-operator-bundle@sha256:883085f67211e3349111154a8a6950e255ec76309dae2f6dade3ffa164ca8801
odf4/odf-csi-addons-rhel9-operator@sha256:33407f39df7e590dbfdd5f89e88d8adfbb93aa46fd42018d77782d3649ad69d8
odf4/odf-csi-addons-sidecar-rhel9@sha256:e5c99b4d682f92e3e886332639c58569573025ea9f55bc6d387215ff48badc90
odf4/odf-multicluster-console-rhel9@sha256:9c88f02fcb66a4c265975a3ecbbb824ab6b056a3a6c8d6c131ade8e2dc5040b7
odf4/odf-multicluster-operator-bundle@sha256:6e981cddf5de0358a8fa80f099ecb40fc662c4a4c61e6f5bb5bbd3df856420cb
odf4/odf-multicluster-rhel9-operator@sha256:ae821a093c65adf8f945ed95c5b8199e4a234d39947ccac95e5f2fc05fbf9ab0
odf4/odf-must-gather-rhel9@sha256:5b4905a8c7bfd28148879af3b8fdbca07c04d9698b2e289a88ca463721d6188a
odf4/odf-operator-bundle@sha256:ded42e337950659ffc28ec0186171f3a3ed55fa148b8cb62c44415705652630f
odf4/odf-rhel9-operator@sha256:74893a2860396b241aaf6a4fddff528e85ee002dbfffa14cf1a524496ef82bab
odf4/odr-cluster-operator-bundle@sha256:c0639309a0acb1fd85e28b09d026ae80882217d6f9a1952792cae09aced26579
odf4/odr-hub-operator-bundle@sha256:42c6ed2fd184e053ad1f4ab35df8a2794c5dcf2f381c0c7dd6313b449fe5f02f
odf4/odr-rhel9-operator@sha256:329bfda361bbec42a2ea7ed92fae2063ae3a1ccb365529b1795c3956a15ac257
odf4/rook-ceph-rhel9-operator@sha256:e73713b136edb855fc590e224606ee26a59d1f7d2f7c9df0edfbbbecb1f48b61

x86_64

odf4/cephcsi-rhel9@sha256:db1204871190698b2cdea55bc474adbb89d3b12d7dfb3cf4ff79f301703693aa
odf4/mcg-cli-rhel9@sha256:b45f7ec1015d98ddd06f1a778d4fe3c5a1a5cb6535048d5ef615e52b9b114530
odf4/mcg-core-rhel9@sha256:a99416cbb0afbe55ff6b8ec968342480223f4d0cc90cd68a31491dec8f080027
odf4/mcg-operator-bundle@sha256:c121cf02ee57b15729377a65cd00acf44eb2727bf8efd0d90cef620f285709ff
odf4/mcg-rhel9-operator@sha256:f25fd47b7b570ffe3bbc4b3282a1813d201be0dac5678590bff7090053107ebd
odf4/ocs-client-operator-bundle@sha256:1f8f4de9ae7cb7a45f118a06d31290b7d93bfb02d5312e42fca98cd2200f5424
odf4/ocs-client-rhel9-operator@sha256:7ffcea75ae1fb5297083fe062d2a32e5f66ed72cdc6b08ba778a2ccf1404eaac
odf4/ocs-metrics-exporter-rhel9@sha256:de0c7f4ca915efb70e74b342adeabd0247df20cb400118b3dfe71fc3470fd052
odf4/ocs-operator-bundle@sha256:836e3c981e431f9ea017dcec200ebb23dc4d6f42b70769433213ef1f61dd591e
odf4/ocs-rhel9-operator@sha256:d2be5fb472e6a95037e74f2e4bd4456ae981412d661ed2ca5765e26ef6c66a43
odf4/odf-console-rhel9@sha256:423da36fc5d7d3ae85216db0c4fa8c026eba08f9e067fc528b7caf229ea2db95
odf4/odf-csi-addons-operator-bundle@sha256:05f6fb214ce10a6d4dc389f05ef329d3e405760ea0b2680066cbd736d26d4493
odf4/odf-csi-addons-rhel9-operator@sha256:2576059d93794c25caf67b517cd6a474ad348f39b3e12d8daeb7d58d973fb891
odf4/odf-csi-addons-sidecar-rhel9@sha256:9a8e03b72afa6b30c33b780ac374b55206f124c041debf58324c24dba6678c33
odf4/odf-multicluster-console-rhel9@sha256:cceabbd5931a9dfae30c50e6ed70f8d284ce74f7cfacc2951e460bf7842fa00e
odf4/odf-multicluster-operator-bundle@sha256:f251460b0ff4ea182f485a362cb86e7b9ef47144850203310673dec5a8f251e7
odf4/odf-multicluster-rhel9-operator@sha256:b97dda76a5559e9dbc521e2d307b2354c8ea34977bac5fa88c78f324b8705297
odf4/odf-must-gather-rhel9@sha256:444b86ad6a0d7ee7fbcf08f98958b1517c80f94618f57eb7cb08ff45aba8feb9
odf4/odf-operator-bundle@sha256:697083a1e480481960ce9ae27a2cf2d90366785803f8aff4608443dc33771db3
odf4/odf-rhel9-operator@sha256:2b93c60b1e1379aa55ef264986407d68287bbcf4bd9995d0177211ae58348c03
odf4/odr-cluster-operator-bundle@sha256:da41f3430b21184cbf346a92b2886fb1dda7ad614ef65346aef1872fc7a23a73
odf4/odr-hub-operator-bundle@sha256:9559432302852253cd6dbe40d022440a0cd4ad6c37c222588d9981cf72bcff58
odf4/odr-rhel9-operator@sha256:dcf2923dd71feba04c015a14eebb59fb68e409b1c5a8a63558866982f2d00a4b
odf4/rook-ceph-rhel9-operator@sha256:5d1a6726559907ed80d85e0af3ab30de8221fc52b8689cfcd2d3cacdc1163cdc

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility