Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:1255 - Security Advisory
Issued:
2024-03-19
Updated:
2024-03-19

RHSA-2024:1255 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: OpenShift Container Platform 4.15.3 bug fix and security update

Type/Severity

Security Advisory: Moderate

Topic

Red Hat OpenShift Container Platform release 4.15.3 is now available with updates to packages and images that fix several bugs and add enhancements.

This release includes a security update for Red Hat OpenShift Container Platform 4.15.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the container images for Red Hat OpenShift Container Platform 4.15.3. See the following advisory for the RPM packages for this release:

https://access.redhat.com/errata/RHBA-2024:1258

Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes:

https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html

Security Fix(es):

  • helm: Dependency management path traversal (CVE-2024-25620)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html

Solution

For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html

You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.

The sha values for the release are

(For x86_64 architecture)
The image digest is sha256:8e8c6c2645553e6df8eb7985d8cb322f333a4152453e2aa85fff24ac5e0755b0

(For s390x architecture)
The image digest is sha256:49cbea5ea2c96c976b9fc65f02866b68bd9be1bb26baf3cf2d7127e15e1d0387

(For ppc64le architecture)
The image digest is sha256:49fb1443be745aebe1470ab2ad6c3780ca24169f8b4bd98cd4cc86a375bd72db

(For aarch64 architecture)
The image digest is sha256:83ef2e8dce0f422926447eefb662d47bf91bce8a8f4ea25640561c251c1282ea

All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html

Affected Products

  • Red Hat OpenShift Container Platform 4.15 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform 4.15 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.15 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.15 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.15 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.15 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.15 for RHEL 9 aarch64
  • Red Hat OpenShift Container Platform for ARM 64 4.15 for RHEL 8 aarch64

Fixes

  • BZ - 2264336 - CVE-2024-25620 helm: Dependency management path traversal
  • OCPBUGS-24086 - Update 4.15 ose-cluster-openshift-controller-manager-operator-container image to be consistent with ART
  • OCPBUGS-25831 - Date&Time values are not showing as per browser default language
  • OCPBUGS-29080 - [release-4.15] Modal dialogs expose code that is not null object safe
  • OCPBUGS-29661 - Bump to kubernetes 1.28.7
  • OCPBUGS-30189 - [release-4.15 backport] The hypershift installer does not set the cipher suites for konnectivity-server
  • OCPBUGS-30412 - CCO degrade when remove root credential for GCP cluster in Mint mode

CVEs

  • CVE-2021-43618
  • CVE-2021-43975
  • CVE-2022-1055
  • CVE-2022-2938
  • CVE-2022-3821
  • CVE-2022-4415
  • CVE-2022-27950
  • CVE-2022-38096
  • CVE-2022-41674
  • CVE-2022-42720
  • CVE-2022-42721
  • CVE-2022-42722
  • CVE-2022-45869
  • CVE-2022-45939
  • CVE-2022-48337
  • CVE-2022-48339
  • CVE-2023-0597
  • CVE-2023-4244
  • CVE-2023-6546
  • CVE-2023-6606
  • CVE-2023-6817
  • CVE-2023-6931
  • CVE-2023-7104
  • CVE-2023-7192
  • CVE-2023-26604
  • CVE-2023-51042
  • CVE-2023-51043
  • CVE-2024-0193
  • CVE-2024-0553
  • CVE-2024-0565
  • CVE-2024-0567
  • CVE-2024-1085
  • CVE-2024-1086
  • CVE-2024-25620

References

  • https://access.redhat.com/security/updates/classification/#moderate

aarch64

openshift4/ose-cloud-credential-operator@sha256:a0426d394fc3c761095ba0a5a950a848a6e28b29a30a028671451d919f6f28f5
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:7e827cd3b4c471c8358ba48889091d27570ff677a4694bb97c4b729958b7aa69
openshift4/ose-cluster-olm-operator-rhel8@sha256:fce9b8f74f4aba59a0bfb1a8f29859d5c820da9503209bdcc3ccd48be84c16ba
openshift4/ose-console@sha256:12d6f3d7e2805fb5992778a0aee0541fc3865dadae1c3a0fc62f3d9c032c259c
openshift4/ose-hyperkube-rhel9@sha256:7496a932300c7f7834b0234c5683dca210b3d160c1c30047daf1c9467bf9c078
openshift4/ose-hypershift-rhel9@sha256:ede27fe3d22d34edf0900d7eac05082aac0427c85022be6221f816f5c9be4292
openshift4/ose-machine-config-operator@sha256:98c49783da2d3c39a9ed52fa0d6acc733533c2289f8515d4c448d934d142f6ee
openshift4/ose-olm-rukpak-rhel8@sha256:233187f8bf152f98cec72512273bf25906ffedbeeeb6bb1a288155707c491dc4
openshift4/ose-openshift-controller-manager-rhel9@sha256:aa9d4271e65286c60578ce2e3940071b1379e75a896dba40774163584bab0d5d
openshift4/ose-pod-rhel9@sha256:d152617edada2d9b9ee5e5f38ac32b44c25fd49932678d6d4c3c18d63242485f
openshift4/ose-sdn-rhel9@sha256:35d6d28b89a1d5204c42ed11541e267a3876af37b811c0e926ea615f66369668
openshift4/ose-tests@sha256:a0fb1c3965fd4dbd7ca8e54e2ae09337548e60465b6006da50c8a223afc51f55

ppc64le

openshift4/ose-cloud-credential-operator@sha256:c7ae92bf193aae8ff3e5069a9a02f2ee1102022e19d95e0dea95e53d758097d5
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:88bcc7f5cc252d66079ee7c4ba610910e8ad96c24f22f704977bb835933f3019
openshift4/ose-cluster-olm-operator-rhel8@sha256:8d8f74b111ba028ed2a6689dd88ac0a5b17deb04e5a967a95a13a50c5370a7aa
openshift4/ose-console@sha256:e2c3a4477638754a138f8554a45e7b4158978363350bbfe5c6d96cd813ff8d73
openshift4/ose-hyperkube-rhel9@sha256:67fcbb5bbe11d0c676e535ee83a747c27650abda00eca9cb161bb682628b5022
openshift4/ose-hypershift-rhel9@sha256:139132fca36a9dd8ea76d35a380f196ca68493f50a015b4a6fa1041fd8c7ee0a
openshift4/ose-machine-config-operator@sha256:2cc3174c2541912cfcadcd8ade47363aa75d4fb80f1a0b712d88ad9fd11eea97
openshift4/ose-olm-rukpak-rhel8@sha256:327c93cc4b860215ff3eab3561d60ff0fc1be9e5c2d1db9ce3832306018617b4
openshift4/ose-openshift-controller-manager-rhel9@sha256:6ed9a16e0777786d589864dc3adacf9a37987c4b24f06b7972b7bf6d7e3b8b0c
openshift4/ose-pod-rhel9@sha256:283b2c4aea7a3030e09d08b150a515f4bb232fbc07f1d960811e665d8fd29802
openshift4/ose-sdn-rhel9@sha256:1c1a66a2de15c279d1356870e2934e9753a7f8e86f7e9497d4272aac15709de9
openshift4/ose-tests@sha256:9ceb22a5aa3ad1da243a42e28ffb91c7e08cfd0b05e7df7d295abb33f956c952

s390x

openshift4/ose-cloud-credential-operator@sha256:17ace1adf247a7db77b4efe82550b78a8cac86e4c3b013dba7f40dab24339811
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:c7805561da209665f1dbc9b97d96f710871b067ed349696d90f79d01665e6246
openshift4/ose-cluster-olm-operator-rhel8@sha256:070f454594088d457a23b131f8e6449e0f71fa91679198d9f0a5c5e83a6bb188
openshift4/ose-console@sha256:b26146adbb150acabea098b6724054bc8ed4bc6e75cc08764f6aea855c0b8e08
openshift4/ose-hyperkube-rhel9@sha256:ce94941d4a1eec73f690087fbabce95ea1a9a51f737e40719dd0e56321f955ad
openshift4/ose-hypershift-rhel9@sha256:a06bec747e5acc847d8b7faec047cded9de6a99859bd42fda5c23e054e87b37f
openshift4/ose-machine-config-operator@sha256:e0648d8cc1ee89c9378f67c0caf0b15c788094dc7f32d64bc0841f1653d1128b
openshift4/ose-olm-rukpak-rhel8@sha256:6f398424939e059aeb27ed3178dfc3374a41ffa40b423c2393cbdc6f64ecc965
openshift4/ose-openshift-controller-manager-rhel9@sha256:e354eaee38e6ee546a01812be7662cfe6fb7039b818428dc1f5671193b4c35f6
openshift4/ose-pod-rhel9@sha256:47cd7555c6f9a54b1f075bfc0e0f9256fbaaf01173794d20fab92508e876fd48
openshift4/ose-sdn-rhel9@sha256:986b1a18efc4f960b23c38b8a6adb588dc1d52cc31be749513cc7d799949481e
openshift4/ose-tests@sha256:727a08dcaa3bd082b93a5d841a4388d4e60725aeec95962717f7cd5a54b90279

x86_64

openshift4/ose-cloud-credential-operator@sha256:9a2e21c79384af07625ee3633ffe4a5062bd40fc79514ad53fcb732c31f9b3f7
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:dc3bd18e5efd55497be564ae42a9452195ac7624ae9909ccbd5bf7cd383d1ad7
openshift4/ose-cluster-olm-operator-rhel8@sha256:2bff65ef9bd4f321ffdccf569772dd48ee84b9b74d8a00313037884d969eed6b
openshift4/ose-console@sha256:3ac3fe5acafec2f6c6e01ef78b4bf32ee4dfdf4f8b811c1be15461e0b6df83df
openshift4/ose-hyperkube-rhel9@sha256:73e86d314d4ec1e5ad0a913dd44a627c15fdc0c62c36a792851bee55c09d8771
openshift4/ose-hypershift-rhel9@sha256:691aed5a56f2f1e2eb6f6d19b6396feacf21e4eb75acb15045a1f2da2acc6f79
openshift4/ose-machine-config-operator@sha256:a332609763a558eeae79bcac4bfd208fe444008c699c9890b8341956f4085e71
openshift4/ose-olm-rukpak-rhel8@sha256:2f28f6449947d6a61a89aba51015d032426ede3518e7fa3a9c2adcbc92f7d02a
openshift4/ose-openshift-controller-manager-rhel9@sha256:9c7c8f54f8a6f04da55322223b214720f88d49fed6e3cdcd958e334ac8d14fa4
openshift4/ose-pod-rhel9@sha256:e69ccab31cccae506a7ed7518026b0481ca039d748cb1b240556a3d1acfcdb35
openshift4/ose-sdn-rhel9@sha256:f54f897d081552e34679f95efa4627de2b5217232dcfe12d478f02815bb702e9
openshift4/ose-tests@sha256:01e5331395b8eb7ccbf4d180aba82fe8d14d9f512ad1924199bc675ab78a2899

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat X (formerly Twitter)

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility