Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:10990 - Security Advisory
Issued:
2025-01-15
Updated:
2025-01-15

RHSA-2024:10990 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: Logging for Red Hat OpenShift - 5.9.10

Type/Severity

Security Advisory: Moderate

Topic

Logging for Red Hat OpenShift - 5.9.10

Description

Logging for Red Hat OpenShift - 5.9.10

Solution

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:

https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html

For Red Hat OpenShift Logging 5.9, see the following instructions to apply this update:

https://docs.openshift.com/container-platform/4.14/logging/cluster-logging-upgrading.html

Affected Products

  • Logging Subsystem for Red Hat OpenShift for ARM 64 5 for RHEL 9 aarch64
  • Logging Subsystem for Red Hat OpenShift 5 for RHEL 9 x86_64
  • Logging Subsystem for Red Hat OpenShift for IBM Power, little endian 5 for RHEL 9 ppc64le
  • Logging Subsystem for Red Hat OpenShift for IBM Z and LinuxONE 5 for RHEL 9 s390x

Fixes

  • LOG-6321 - [release-5.9] Disable automatic discovery of log level in Loki for OpenShift Logging
  • LOG-6376 - Fluentd is not generating correct configuration when used tls.insecureSkipVerify=true in HTTP forwarder output type.
  • LOG-6377 - [Logging 5.9.z] Infra namespaces spec'd as app inputs have log_type set to 'application'
  • LOG-6044 - Multi CLF validation failure when adding a namespace which contains "kube" or "openshift"

CVEs

  • CVE-2024-2236
  • CVE-2024-2511
  • CVE-2024-3596
  • CVE-2024-4603
  • CVE-2024-4741
  • CVE-2024-5535
  • CVE-2024-10963
  • CVE-2024-50602
  • CVE-2024-55565

References

  • https://access.redhat.com/security/updates/classification/#moderate

aarch64

openshift-logging/cluster-logging-rhel9-operator@sha256:55fdeaaab6d854f6809fedc61ee007e386816e91aef01130967b1ea6db2a4909
openshift-logging/eventrouter-rhel9@sha256:8ffc27143546545c8d3e6445f617e3742f43a560daecbfb1d15bf034999eee1c
openshift-logging/fluentd-rhel9@sha256:3b49c0d049de29b177a5133efc17a6d36f63a2b4f506b5c6066f729f373afc6a
openshift-logging/log-file-metric-exporter-rhel9@sha256:5f1c0db8c0de5ea9f48d33f20702a27072f61186b46e4f297eee7d20c17fe231
openshift-logging/logging-loki-rhel9@sha256:2b28cb1511f37234a0c990a6a0f69e2badb72444c3c956a9847c30fcd9c85ae5
openshift-logging/logging-view-plugin-rhel9@sha256:d8866091ef38cb40de871b687442eb3bcef946e9bf7facec8a7df40f7c41d356
openshift-logging/loki-rhel9-operator@sha256:86548ecd21cd6330e955b4b95357b8355fc69658c1c036ae8c672666b3c5993d
openshift-logging/lokistack-gateway-rhel9@sha256:20551b59fd9e4d201f95f439cbb2b8fab74d4f4b5749487040e349e01603f6ac
openshift-logging/opa-openshift-rhel9@sha256:71942d465a467ea4d7bb3703c48e05562d3b2f91cd67f1bc281c2523f66b3c65
openshift-logging/vector-rhel9@sha256:12342bf8a0a2bde2b4f9ac97bb442b9c5c4b5545b32f5a3e2a80afb36cd99086

ppc64le

openshift-logging/cluster-logging-rhel9-operator@sha256:a656c97dac4eb98c9e8b65a2b690c0e44fbd30ebc80080f69e4fb0f55c00b1cc
openshift-logging/eventrouter-rhel9@sha256:4c2aeae65b21def30fddc7f44f4a6f67318a7fa10feb69670d5abd82ce18dc34
openshift-logging/fluentd-rhel9@sha256:1220652da3bc0ecb7c3739695d39ca5e4d68ddf5cee523a99fa66e459ab6e184
openshift-logging/log-file-metric-exporter-rhel9@sha256:672d83a78de568ec9b336cb648d0cf3ebe572cb0db778786ba0359ae550d60e2
openshift-logging/logging-loki-rhel9@sha256:59677e0136685e9711200ca72371281773ff0dc85105b3547c860af559cd44a7
openshift-logging/logging-view-plugin-rhel9@sha256:0d6a0b26c3124d8770dd1a8202d4fe430be0c42f0c9c0821b9647a732dec45d7
openshift-logging/loki-rhel9-operator@sha256:5eb3f91a404821ee0c409a6aefed194f974dacc7c1cda70f53dcbf0de1870222
openshift-logging/lokistack-gateway-rhel9@sha256:6a75b26d66f7c91ce846f7e8afa6945761629fe5aaf180ede570d70caebd89a7
openshift-logging/opa-openshift-rhel9@sha256:609aa3d4c34ee33efe07ba421c462e1e54db62caf4e15805352b1703d75f91d3
openshift-logging/vector-rhel9@sha256:08eb9ae77aa2b7fd68da9953bdb123a6f14f3b74218f9ca632e16d33914bc4f9

s390x

openshift-logging/cluster-logging-rhel9-operator@sha256:635d7fb09f675ef562bb3bbd143b781ed31a2fe337a177fde9cde641913215b2
openshift-logging/eventrouter-rhel9@sha256:7d907b24fc58d8d81d6359781595b69953df6eafc4658e45466cb0aa4f7292f5
openshift-logging/fluentd-rhel9@sha256:b50563322ca6527cc95c02756e987c294a9f265895c3cae6797df59c9bd64209
openshift-logging/log-file-metric-exporter-rhel9@sha256:15a6177be46dbc9d8ac34b9e80e2cab82c71c0a879465e23f6341d4dc38e4c79
openshift-logging/logging-loki-rhel9@sha256:9fa9425992b4e74a9434a07b6fbc8febec6b0032bd58768735636ac11cca1b12
openshift-logging/logging-view-plugin-rhel9@sha256:19a31e246c9a8fd785bcd117fcca94841442da65054875787bcb304147c74252
openshift-logging/loki-rhel9-operator@sha256:a568b88161073c830dd3bbf00085e439e3ffaedf5d4a88fa382ddf13b91cb08f
openshift-logging/lokistack-gateway-rhel9@sha256:6e4b326d40b4a8840c471c3ee1bfbe1760c307c6274e4cac50765d06b54eda43
openshift-logging/opa-openshift-rhel9@sha256:f4ee9465524008e0b211e3240d6eb83a9f189ee3770a33806f3aeb9c6499dfd4
openshift-logging/vector-rhel9@sha256:96cd652bbd1886e4af7690e178d361f2b8b827aaff1b9f2908b899a1262ad979

x86_64

openshift-logging/cluster-logging-operator-bundle@sha256:10cf06ab045cd5621c85b7538c29d62b4a584cebeffd5a3801a61f7f9fa59e89
openshift-logging/cluster-logging-rhel9-operator@sha256:704f1a88f4ea84d75bd263af732542361dc7ff0976151aee4d9ba14d167f1b4e
openshift-logging/eventrouter-rhel9@sha256:403e5c062b6346f393326b204b3deb644322e92cccf349f42a2ac2b171a5537b
openshift-logging/fluentd-rhel9@sha256:a8acadc8b0f339037742318b25581f44ed7371cd41b189f5bfde37648d08a47e
openshift-logging/log-file-metric-exporter-rhel9@sha256:e8f1eaf73fcd414d8dbe551a9f509ec777b663614e976c9c2fb4e725f26e81a0
openshift-logging/logging-loki-rhel9@sha256:cab79d832e139bfa0eca4d60b7162200068fecd0f4d73ba16a20f2455b8a98d5
openshift-logging/logging-view-plugin-rhel9@sha256:00446b1e1864c1d2673a987df5c737bd258700ef7220f4932cd7612b0066f200
openshift-logging/loki-operator-bundle@sha256:219701c6ddb44c878755a08b7e54e26e3735e6d69187eb3cee06295b4da7cf1c
openshift-logging/loki-rhel9-operator@sha256:86bff4ad0313017ce35d9bc9eabd975919bf0fd37dd86fa0714ca9307c78a0f4
openshift-logging/lokistack-gateway-rhel9@sha256:90fd53a3cdd7a7cc86f2992aa2d73226f4b08cf0a92cbb1ebfc48730fd07c5fd
openshift-logging/opa-openshift-rhel9@sha256:28592969d803e47bc514b23e67495a9f256580c42b2bea837bd178ac63dcef38
openshift-logging/vector-rhel9@sha256:56c33e8f94df48910b85233a2e368db0364051259a8811d216c9bd3657061c0a

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility