Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:10988 - Security Advisory
Issued:
2025-01-15
Updated:
2025-01-15

RHSA-2024:10988 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: Logging for Red Hat OpenShift - 5.6.27

Type/Severity

Security Advisory: Important

Topic

Logging for Red Hat OpenShift - 5.6.27

Description

Logging for Red Hat OpenShift - 5.6.27
dompurify: nesting-based mutation XSS vulnerability (CVE-2024-47875)

Solution

For OpenShift Container Platform 4.11 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:

https://docs.openshift.com/container-platform/4.11/release_notes/ocp-4-11-release-notes.html

For Red Hat OpenShift Logging 5.6, see the following instructions to apply this update:

https://docs.openshift.com/container-platform/4.11/logging/cluster-logging-upgrading.html

Affected Products

  • Logging Subsystem for Red Hat OpenShift for ARM 64 5 for RHEL 8 aarch64
  • Logging Subsystem for Red Hat OpenShift 5 for RHEL 8 x86_64
  • Logging Subsystem for Red Hat OpenShift for IBM Power, little endian 5 for RHEL 8 ppc64le
  • Logging Subsystem for Red Hat OpenShift for IBM Z and LinuxONE 5 for RHEL 8 s390x

Fixes

(none)

CVEs

  • CVE-2018-12699
  • CVE-2019-12900
  • CVE-2024-9287
  • CVE-2024-10041
  • CVE-2024-10963
  • CVE-2024-11168
  • CVE-2024-35195
  • CVE-2024-47875
  • CVE-2024-50602

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

openshift-logging/cluster-logging-rhel8-operator@sha256:c935a5b7ac52794faa082ed4af1ad33023142649bced40ef68d9f3524a54c31c
openshift-logging/elasticsearch-proxy-rhel8@sha256:d8d7786e4fbadd954777bb20e8da1f82bd79aa36e1c95d46d286974c7233114a
openshift-logging/elasticsearch-rhel8-operator@sha256:d7c3a9ea153838949455419541456caad8432ec81fd279f694f6cee03374d50f
openshift-logging/elasticsearch6-rhel8@sha256:bb3b67b37cebd13f8e7623043eab4c17ef2e8be2b34407cee154037d53c8fc8a
openshift-logging/eventrouter-rhel8@sha256:e3d38f53d567c627332670412ac22b1ed860a72595959cb810b9f022ebf57371
openshift-logging/fluentd-rhel8@sha256:07f8be119ffc987a1def8a352fd65333b6d91f89935b3540ae6af6f1f51b7c12
openshift-logging/kibana6-rhel8@sha256:8c23c358103bc35851dd5e23a648f950950f24488f475ce53dd0fa314eee2a3d
openshift-logging/log-file-metric-exporter-rhel8@sha256:e3f2aa5b3f0ef12df86ccae168daaf063a192945a3309c94e803330767cb2bb8
openshift-logging/logging-curator5-rhel8@sha256:74194d6c98612ef801b6db82ccb7344bcf7aabda9ca5147c425c178a9bad06fc
openshift-logging/logging-loki-rhel8@sha256:de38204f57c1248e04c88762e149aba5df0a5c9724629ad55a7e9cae4aa43a38
openshift-logging/logging-view-plugin-rhel8@sha256:71442ccb07d0eb2e1cebb56999ea17ebc0a2bb8c410bcb5a1364b401d4489e5d
openshift-logging/loki-rhel8-operator@sha256:7ddeb8e957f3db9a8b7e9cf7507025da18636fea1bffd9359aca2b2e51e999df
openshift-logging/lokistack-gateway-rhel8@sha256:2fceb9cb2b2e399a6a1726f369ec7ee75443aa3d40514ada5e802a4fd46f6652
openshift-logging/opa-openshift-rhel8@sha256:9b15ca5dfaaa765bdf62a7fc7f566972810bc94f506d41731aa1e85ff2c914f5
openshift-logging/vector-rhel8@sha256:769f184481ae8bb036297a9d627da22fdfae2880bc93ff0731a1caa16bde6174

ppc64le

openshift-logging/cluster-logging-rhel8-operator@sha256:bd7a3c5ee7cd28b89dcf215818f7f10b360c1b91bda152a3169dd96c6c7d6f32
openshift-logging/elasticsearch-proxy-rhel8@sha256:b01d8f4a9c22decf6a7f5b90102e875f09da97f687dee9cd26044384b513afc2
openshift-logging/elasticsearch-rhel8-operator@sha256:edef1b7e0d9b4c60ec91d572927feb4d6208e0eef81d3de6b1b5c10dda828935
openshift-logging/elasticsearch6-rhel8@sha256:d3d9fdb4ba1c333b86e725434d83cc4d80ab2dd3dec1008ee4806f8c32d4d8dc
openshift-logging/eventrouter-rhel8@sha256:d2025015086f1d133e48ad8ab11755c459d555a960d1faa98ae7ff7c8e4c7001
openshift-logging/fluentd-rhel8@sha256:1192ec065c0f370676f2ae985c48bec7a227cd2ad904b241b990e5edffebf4e7
openshift-logging/kibana6-rhel8@sha256:df6f2da31202e0e37db1bfc5fa5d5f8d7dae6cf06c4eb32751b4aa58698cfd45
openshift-logging/log-file-metric-exporter-rhel8@sha256:c633886066fc1a153b25fd2462cd7c0415127fbc081713acdec211f898484c32
openshift-logging/logging-curator5-rhel8@sha256:e1213e89bff691e9d7f127f7441166badcf89ecc2cd5dd7f706394f1300f4071
openshift-logging/logging-loki-rhel8@sha256:17c01ff2506e453f0c99dd81011d10d9dfabdad459eb9bd7c7e5824524a15aa5
openshift-logging/logging-view-plugin-rhel8@sha256:f885eb04eb154f24af60598752555717f0232bb5c1e48c546f447f2dbb102212
openshift-logging/loki-rhel8-operator@sha256:ff9b4417774e5c27cf8148f4021b59f01e26cd531bbbded9edfdd871bb39949d
openshift-logging/lokistack-gateway-rhel8@sha256:b649c6dfcec18c74ea29b08b7f58b249c3b75b0d20a3e8fab9a05c6f802e9d23
openshift-logging/opa-openshift-rhel8@sha256:2f560ace1a46c8dbe9675bc81b8b137447554266080306efd040a050853d2986
openshift-logging/vector-rhel8@sha256:2b48a07dc7ba0884385a4735e70bb13d7bea6e46ba70d3c997ef15d924c70f30

s390x

openshift-logging/cluster-logging-rhel8-operator@sha256:15a96df5ea7cd1046a2814b46e540ea0ae31f3c819285f1a29a2d6e24ce35740
openshift-logging/elasticsearch-proxy-rhel8@sha256:3024818a3ca77f5351877cc72924fdf824eba6defb4be080003d03334aba131c
openshift-logging/elasticsearch-rhel8-operator@sha256:6cef416969162696d637aa40de200b5926eaa8cff07621392147fe338e40610e
openshift-logging/elasticsearch6-rhel8@sha256:cffe2b974c01b90354dee33bf25bf4031ad59a41353de2035cb88a27f59fa7a4
openshift-logging/eventrouter-rhel8@sha256:ad09dff23d8ea0cdfec735667381fb6d337172b14a38ae62c162539d7a848898
openshift-logging/fluentd-rhel8@sha256:2ebf1c87d632c563050f3f5b5ced103f3275662cd44f3da77fd6428fd7d40ee3
openshift-logging/kibana6-rhel8@sha256:bea734b98fd4c0123eb4803d8a0c9af797b384c3bf437aa02bb572588a04c805
openshift-logging/log-file-metric-exporter-rhel8@sha256:1d7cb038a05735ec60c4de8d070dc431526a486842b582ee41cc38c42fb7ecd6
openshift-logging/logging-curator5-rhel8@sha256:a56ffd2c5c413521b7287f2b4506c985bd460024914a2bb914015705ea206f13
openshift-logging/logging-loki-rhel8@sha256:905142b9beb554a1c593a8a8207b8a6669c84e40a809aa1a1ec7756cb09e15cf
openshift-logging/logging-view-plugin-rhel8@sha256:2414e3c9f341e04ab8df7ec67913eb1f48b5261a9922302ef08e6faf1d656667
openshift-logging/loki-rhel8-operator@sha256:84620e7d2921f59b6b5e0f8fc0984704fbec96454d55a92c39cbbd2b1a542752
openshift-logging/lokistack-gateway-rhel8@sha256:9deb3fab51afb48b3db267a0656350752d470386af6102646809ea027d9f9d93
openshift-logging/opa-openshift-rhel8@sha256:cdf75d4f02905bf4d4e1376e15099fc0098463e74fdfa854947b7a70510a3a52
openshift-logging/vector-rhel8@sha256:3e152577d75d5b1cf75977f3ed078804575c0eeedb3132b85a0db4db5e5de45f

x86_64

openshift-logging/cluster-logging-operator-bundle@sha256:2e00756b71612c2d08cb9f9f1ba7bb9507a460ccb9c0c4c82458f8fc42a72dfd
openshift-logging/cluster-logging-rhel8-operator@sha256:897e5220fd28e5ae8bf4c2af746e43eb7d121f9f9929735edb7f2c4cd56d5fd9
openshift-logging/elasticsearch-operator-bundle@sha256:8e3bbb5532dd2b4531c940eaca72eac72caa8e845fe4bbe3310bc82760a9a8af
openshift-logging/elasticsearch-proxy-rhel8@sha256:1333d71476a58eded72ffd77c12a26329f13b037dd49f073862d3a3eadce0f2d
openshift-logging/elasticsearch-rhel8-operator@sha256:83fde07cd0688abff5a6527e6fa76adab13d2c4db534c89955ef34b0ca706f43
openshift-logging/elasticsearch6-rhel8@sha256:82346c7142795d09a6e6e057edcbe6af08481dd243e927970fac762ae43348ac
openshift-logging/eventrouter-rhel8@sha256:7545cc4f956931c0b94b91924411700cd15ea09a36431a9704bbc01079c5cc6f
openshift-logging/fluentd-rhel8@sha256:6d04672d8e96e199018a0e6b3781475cea0fe0032d4ef66feff2999d6631b453
openshift-logging/kibana6-rhel8@sha256:17ed92de8fe4c80b45efe3710ade28d1058569725ed3a826774908580aa3cb0d
openshift-logging/log-file-metric-exporter-rhel8@sha256:24d597fd8148a249907a76231de1c591eb2289dff3693779479a15573c57cb0b
openshift-logging/logging-curator5-rhel8@sha256:d71b128a8d3a2842d6d07cc45f71c53449543fba80edf9153a164b64a4d19e5c
openshift-logging/logging-loki-rhel8@sha256:98ffce85b4088a7cfe201f8e87cd9523e0b675d49fb26692cebf72854c38d931
openshift-logging/logging-view-plugin-rhel8@sha256:2ef85a419f5c258d0d4a474cfc4b6595bb8ac0192a61a788229283c5f40e776b
openshift-logging/loki-operator-bundle@sha256:cdbcfceb30316e3232f6faf85578ab51ced0f30d8ad8325a8f133470e64035f6
openshift-logging/loki-rhel8-operator@sha256:19525656106ccf6990d088a55c09b6700f5dc1fadd6fe0b6f754f0200c0569e9
openshift-logging/lokistack-gateway-rhel8@sha256:75b0954ad6ad4ae3f5d727beff8cebeec68d9190caf164389bf317e6bebcadfd
openshift-logging/opa-openshift-rhel8@sha256:cb2e78c47747712f91ea4623216993d26118cf729f8d8194a4d8cb6a20e681c9
openshift-logging/vector-rhel8@sha256:9dbb868330ce495c914c6b42c24fb79896ebb9f2392281f1571e65ea5ecf97ef

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility