Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:7820 - Security Advisory
Issued:
2023-12-14
Updated:
2023-12-14

RHSA-2023:7820 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: Red Hat OpenShift Data Foundation 4.12.10 Bug Fix Update

Type/Severity

Security Advisory: Moderate

Topic

Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.12.10 on Red Hat Enterprise Linux 8 from Red Hat Container Registry.

Description

Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3-compatible API.

All users of Red Hat OpenShift Data Foundation are advised to upgrade to these updated images, which provide these bug fixes.

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Data Foundation 4 for RHEL 8 x86_64
  • Red Hat OpenShift Data Foundation for IBM Power, little endian 4 for RHEL 8 ppc64le
  • Red Hat OpenShift Data Foundation for IBM Z and LinuxONE 4 for RHEL 8 s390x

Fixes

  • BZ - 2126299 - CVE-2021-3765 validator: Inefficient Regular Expression Complexity in Validator.js
  • BZ - 2244765 - Update the ceph image to RHCS-5.3.z5 in ODF-4.12
  • BZ - 2246334 - [4.12.z clone][MCG] RPC method "list_objects" fails with "RPC: object.list_objects() Call failed: failed to WebSocket dial"
  • BZ - 2247112 - Include at ODF 4.12 container images (7) the RHEL CVE fix on "python3"

CVEs

  • CVE-2007-4559
  • CVE-2020-12762
  • CVE-2021-3765
  • CVE-2023-4641
  • CVE-2023-22745

References

  • https://access.redhat.com/security/updates/classification/#moderate

ppc64le

odf4/cephcsi-rhel8@sha256:59fa82c420af8e3f8dd1695b121eb64c59f76f803770c59fd5c9025a64032663
odf4/mcg-core-rhel8@sha256:5badaef19e5c3db4aae1a050212fe7e11e2ffdd9b232da5427b03fa075a1bcb8
odf4/mcg-operator-bundle@sha256:b21ba1915554201c5ef43abb66eac13482593fe31ce05a72cf909e4f385f5daf
odf4/mcg-rhel8-operator@sha256:78aa0073d7959991ce47558ae58a51966d237953acdce97e3118d108f0c398e8
odf4/ocs-client-operator-bundle@sha256:fbcd8ca8bf948eb61168513d162ed8ae0fc15583131984981d395dbed1df613c
odf4/ocs-client-rhel8-operator@sha256:9cf0c0be2573f66f3c8324edbba9cea51e003d97bf9582be3aced5ff0d9a743c
odf4/ocs-metrics-exporter-rhel8@sha256:b527a1f2013d7af593ce1611eaa6c091370b80b3612638204ab6bc061d731dc0
odf4/ocs-must-gather-rhel8@sha256:4e14d564a967f545ba76d0965f1f60da2c49284e5fddfed2b21972012dc6c7c1
odf4/ocs-operator-bundle@sha256:bcb41572adbe0bef128b29ed9541a2f46730b80e8cb178d47b1c3ee0dbf89b46
odf4/ocs-rhel8-operator@sha256:fc75d7525aa3b9e12cf14ecbd99d79c070b3ff4417afdca014e6de70203a9d99
odf4/odf-console-rhel8@sha256:6029aded51d62d9ca0104cc59754f6349c5e70cf7846c6ac94470715e491a003
odf4/odf-csi-addons-operator-bundle@sha256:0f33b6e8f7022b09dfeb92926783d39f3635325d4a36f82ae534cfae8c7b0a3b
odf4/odf-csi-addons-rhel8-operator@sha256:50957f5abc4e913bce3a59cb41f9ac8186d876b11a7417c65eeeea829953a66e
odf4/odf-csi-addons-sidecar-rhel8@sha256:99213f9f76cd01eeca7e8c53a81a4a72ad3a64906a276df3990872f776c1019f
odf4/odf-multicluster-console-rhel8@sha256:14c2c8f9467a5b51ea37911e52d007a3b0b7e921436acfa0797e432ee222cc6b
odf4/odf-multicluster-operator-bundle@sha256:d1a072978417714d1917368baf27045b9922987f5c54a9f30ba473e73c913fce
odf4/odf-multicluster-rhel8-operator@sha256:96efdffd9c3f43d1cbed3468b6d4882e1e7a78f1aaca495c0e28e8cbbf71e540
odf4/odf-operator-bundle@sha256:a28d1908375442b6e8ef009b40a8ff9a16653c7948455f43afe74fe06a505518
odf4/odf-rhel8-operator@sha256:923c511cfdfd1fe1ceb47d627355bd8fa1cbfb30afb4d7b5b6f2cb2505c862ac
odf4/odr-cluster-operator-bundle@sha256:fbf5a432e4dd07cf5a3e115679fcebd5e8e6f8070de50b147f04a947bf107ccf
odf4/odr-hub-operator-bundle@sha256:d4976746183e773fa777de5ae25f1753c7b1fd137bd88b7cc54af485af1cabc7
odf4/odr-rhel8-operator@sha256:31c71fd8876661f6d2cb124aa9b090c445701b6f1ecb63d07dc0cdd462338c72
odf4/rook-ceph-rhel8-operator@sha256:02fdf30836dd523a00d4953e3ecd742e557d8665b555fd4ea676aa042d023de9

s390x

odf4/cephcsi-rhel8@sha256:c4748e43addf26e45b55f83d880fc82a9e1bb22e37e3b2e7f0f1348292740641
odf4/mcg-core-rhel8@sha256:392340e4fd5a34c5e7daec8cb03bfd8ee256cc44a5358fab9aa598a5e6b23efb
odf4/mcg-operator-bundle@sha256:a80f396cd90b7118d6eb065a6d47969bf77386419559531c59ad8c025af89f9b
odf4/mcg-rhel8-operator@sha256:606eaed06a442f11481538e980bf3a78db7f788f8008c410e49de6f8dcf2feb3
odf4/ocs-client-operator-bundle@sha256:64fd66b088db2e61330c1d9fe3e51ab1136814855987dabf3087e20948ef9718
odf4/ocs-client-rhel8-operator@sha256:f9acde458aa1cad7e8e20f9d29600c4e157ee9abef94fdab44a3e18389b7ddf6
odf4/ocs-metrics-exporter-rhel8@sha256:3cf36e925f9661565fdfb3ffbf1443ef432788cba4cb6374f2d1b2120b94171b
odf4/ocs-must-gather-rhel8@sha256:236b118b12fbd84139b4a4bd1b11577fb3b4defdda8f81410aa9d3d94d091dbb
odf4/ocs-operator-bundle@sha256:747dfd6f76eacea2f2d947e4d8130ce0b0122f9cd932f4c64854d0ce164eef27
odf4/ocs-rhel8-operator@sha256:7911982f807eda446a87a477ec75ec1d0908303c1c851ba717963c3ae64f2f9d
odf4/odf-console-rhel8@sha256:dca1df957b61491aa2964606f443a127a0d6afc500ad3c3d24c9178821b81c8c
odf4/odf-csi-addons-operator-bundle@sha256:ab492146266cce67917cbed2f5bc1266c895f4f863790a487d5a4295b0805896
odf4/odf-csi-addons-rhel8-operator@sha256:00ee14dc29e19896966cc83c2b9ecf8ef0adace88784e836e14941c4c715c2af
odf4/odf-csi-addons-sidecar-rhel8@sha256:949e9256a096c2ce8a9423b0e5b43b437edf2afcea4562ce1fd70ad89dbfb3aa
odf4/odf-multicluster-console-rhel8@sha256:8fc8649474dea8d569636414cf1d4546c7ae8d7f1600f678ea5702cf20251127
odf4/odf-multicluster-operator-bundle@sha256:4e97d3e07ad45206bc348682f3ee7c3dedc084f452394b5edcd8791b820293cd
odf4/odf-multicluster-rhel8-operator@sha256:27120e653977f168ae971f251c56d7d81243d6af69ab4ef18dce6c5546dd9641
odf4/odf-operator-bundle@sha256:d65ee2f23a5589b84b1959bf22660654a28a702eb095241f268fd3fa77224ae6
odf4/odf-rhel8-operator@sha256:612d6f2d7d3708ccaf7fb2f2a8088c37192e71e8370565adbf8fb187027527cd
odf4/odr-cluster-operator-bundle@sha256:84dab997597a901ca01d32001eebac23915e5bacd9ab34dc940a48d46b914d68
odf4/odr-hub-operator-bundle@sha256:12264b29008b1787d05c11eae8cfb87cfc3eb328360b76f8ca7517c32a93373b
odf4/odr-rhel8-operator@sha256:d9497c673469dc9dbc9b4a44fc7fa8fcdb7e795309d721660f5baa302f2b6ba9
odf4/rook-ceph-rhel8-operator@sha256:52e0d2321492b43162d0fbd9b219ded55a5445442e8c92f9060d3479ef781bb6

x86_64

odf4/cephcsi-rhel8@sha256:9f4cb5a11dfa61981c6dadd991d3e90e9ca8e2cad5faed24d5f15fe940f05227
odf4/mcg-core-rhel8@sha256:44da9b1743a5462240da1dd26217a41c9f0c56355d1e4c9f568db08b59be3072
odf4/mcg-operator-bundle@sha256:11d39cdbab29d92bec64010995279f05a83d99cb55965b9f6d057ff8a43da75e
odf4/mcg-rhel8-operator@sha256:e95907b1a04b7f59bdb8e7e7a4cbfa996079485288aa9fe10b7148a832b10951
odf4/ocs-client-operator-bundle@sha256:fc75b551c40cdaa9341d376ff7f864d5f9181bcb980923325fa7432e7063a13f
odf4/ocs-client-rhel8-operator@sha256:adc09956f55af7e021e3569d0291b3fc7fb3165eb665d41c9169f4b1d1011ecc
odf4/ocs-metrics-exporter-rhel8@sha256:1d330903fd2a458e81159eedb3e97e76fe4eb83ed71237c8753ec2489a929b41
odf4/ocs-must-gather-rhel8@sha256:818620ff8d86e41b4c8b183955e983ab08e90a04c2aab5c1ebbce8d241bdbd1c
odf4/ocs-operator-bundle@sha256:f01081270128adaca2f0305213548b1c3958a16b698473803c2f1b1d678cad1f
odf4/ocs-rhel8-operator@sha256:40aa0fd89dfc6ba1744ada546bc778c28ceff4b1ff7c31fb935010804d299d4f
odf4/odf-console-rhel8@sha256:c4e2d1cef288d4756c23ec949f75eed26f8d3374d38ec805fae43568a1880cc7
odf4/odf-csi-addons-operator-bundle@sha256:524023bc8569230721f9f7526034e7793dd50d03d931a2de910af5affaca4f4f
odf4/odf-csi-addons-rhel8-operator@sha256:7e54f2580f21158b97f0337f0f04810b271e1aca6372a4873ee6b73ececc6dd3
odf4/odf-csi-addons-sidecar-rhel8@sha256:815182de80bbdd2060c56998bd5615c0cc6114dab00b217a31642000d4f82455
odf4/odf-multicluster-console-rhel8@sha256:e66317f4a8a4c71322758f5c358efb264c20f30a6c0d64b20c0671385e4a051d
odf4/odf-multicluster-operator-bundle@sha256:ec8527c4194453ae3fa7fedf9f11eb8e70f46f272736ac8c32e98b822a0a049f
odf4/odf-multicluster-rhel8-operator@sha256:efa747eea65f274f6a5d80f7a56f9c6387a806e3a5563483ba3adca4af36a130
odf4/odf-operator-bundle@sha256:513ca9ad731c00974a673e1d7489c60b63d698db26c3389a23690483fc95cde1
odf4/odf-rhel8-operator@sha256:6a5d45c0c5d74cbcb406ecf1cd7a369b827fc64d08d3d213a53a9d41e9a14a17
odf4/odr-cluster-operator-bundle@sha256:f9f0ac32f276f04b8b1ac2c158f0d5c2f4873d3166a4e762e4e04561fa401370
odf4/odr-hub-operator-bundle@sha256:fa2b5dd7db7bc0244660d7b4f95a2c06a6fd12a35f1e66449b85ac628cf960b2
odf4/odr-rhel8-operator@sha256:deeb1422b359205583435060b077931bcf0bf2c058caffefc27963969a370170
odf4/rook-ceph-rhel8-operator@sha256:1be6b92bc1258d63aaaae0036a6ab99a5223c86b2520deac2c939d3e6332bedd

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility