Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:3473 - Security Advisory
Issued:
2024-05-29
Updated:
2024-05-29

RHSA-2024:3473 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: OpenShift Virtualization 4.14.6 Images security update

Type/Severity

Security Advisory: Moderate

Topic

Red Hat OpenShift Virtualization release 4.14.6 is now available with updates to packages and images that fix several bugs and add enhancements.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

Description

OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform.

This advisory contains OpenShift Virtualization 4.14.6 images.

Security Fix(es):

  • axios: exposure of confidential data stored in cookies (CVE-2023-45857)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Container Native Virtualization 4.14 for RHEL 9 x86_64

Fixes

  • BZ - 2248979 - CVE-2023-45857 axios: exposure of confidential data stored in cookies
  • CNV-39569 - [4.14] CDIStorageProfilesIncomplete caused Openshift Virtualization operator status go degraded
  • CNV-36026 - [4.14] Clone takes more space in 4.14 - on hostpath-csi-pvc-block storage

CVEs

  • CVE-2021-25220
  • CVE-2022-2795
  • CVE-2022-3094
  • CVE-2022-48554
  • CVE-2022-48624
  • CVE-2023-2975
  • CVE-2023-3446
  • CVE-2023-3817
  • CVE-2023-4408
  • CVE-2023-5517
  • CVE-2023-5678
  • CVE-2023-5679
  • CVE-2023-6129
  • CVE-2023-6237
  • CVE-2023-6516
  • CVE-2023-7008
  • CVE-2023-7104
  • CVE-2023-45857
  • CVE-2023-47038
  • CVE-2023-50387
  • CVE-2023-50868
  • CVE-2023-52425
  • CVE-2024-0727
  • CVE-2024-2961
  • CVE-2024-22365
  • CVE-2024-25062
  • CVE-2024-25742
  • CVE-2024-25743
  • CVE-2024-28834
  • CVE-2024-28835
  • CVE-2024-33599
  • CVE-2024-33600
  • CVE-2024-33601
  • CVE-2024-33602

References

  • https://access.redhat.com/security/updates/classification/#moderate

aarch64

container-native-virtualization/bridge-marker-rhel9@sha256:639585e4679ac391d08650b9400bc4b60aec11c6ffaee475733b689ea8e4cadc
container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:19bde57fb40cbdbae89a3607752d52b0066f5be773206014c8355c1212162229
container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:e3939de05b6da8e0abe8f563f4fd6539d8609e660c42c8838c7ee12dae6ed372
container-native-virtualization/cnv-must-gather-rhel9@sha256:51b9251dab6504df1b278dc5189ea62512d13c107233d2008c584fe43ef4fa2d
container-native-virtualization/hco-bundle-registry-rhel9@sha256:1381ecaed442162e985372cfc07d8189fbe3cef4a32f801d6838c1d9c669b1e2
container-native-virtualization/hostpath-csi-driver-rhel9@sha256:363a3e53ff526890421817fc89f57e2e3a8f4ee3c40d937c0bbab519973b4079
container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:1c6d9c60ec73a64433dcdd1675d0e4cc8a5fc90ea908329b8afe1b2d8782a411
container-native-virtualization/hostpath-provisioner-rhel9@sha256:13c4e9e02600414484fb7a231597256e90fbd587b71d836771b7a794c4bf8d62
container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:437cc3bbab2422e7419f786621e7a2098168b81c7fb96513b105ded0e12ceaff
container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:ea09a1a79fff02ca0ce74433384e338c3674bda72d40403a2e7bb6145b3f0ecb
container-native-virtualization/kubemacpool-rhel9@sha256:93efe34fb309b9d9d1b36f167976baf65a297b0b8a6d32ce67160889dc4ad733
container-native-virtualization/kubesecondarydns-rhel9@sha256:2cae124766b49ee4e07a83c7d0929279e4161301dbc0bdeb0cd1932e35ecd24a
container-native-virtualization/kubevirt-apiserver-proxy-rhel9@sha256:177d2a0a12b6c6fe5d261d524bc9c09760099f959edcffae7d8bc925f170db8f
container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:e2fedd04de0acf0bd947d69709bdbe6e726bccbdd74fa9619a7ae553add22a52
container-native-virtualization/kubevirt-dpdk-checkup-rhel9@sha256:6c21c65dc271f36d9215c31976a35d66f66b7902170347ae0097a1060522845e
container-native-virtualization/kubevirt-ssp-operator-rhel9@sha256:44bc36ca60c6c25c71796c2449d90f210eb577b0f2f8734ae0f3e44d01a9ac2c
container-native-virtualization/kubevirt-tekton-tasks-create-datavolume-rhel9@sha256:1d0bb5322bf9c035b216f9a560fddd5cf44e78f9a8793b0a75abb73659e8bab1
container-native-virtualization/kubevirt-tekton-tasks-disk-virt-customize-rhel9@sha256:0f29cd8779347683fd469d697bf582b31770dfe0fc5aea101e06824a76801fdb
container-native-virtualization/kubevirt-template-validator-rhel9@sha256:2d43903a285a361ebf7bb348809ab9b8cd9f413a57031247db82c611f1abce4f
container-native-virtualization/libguestfs-tools-rhel9@sha256:9c718cf14f8a8897e80d186e2db67061b29851d0066b20743b2cca228960dfe6
container-native-virtualization/mtq-controller-rhel9@sha256:552dad2ca8669ff1a2a05c40de39a237feefbb308872b1eec7baf70a545215bc
container-native-virtualization/mtq-lock-server-rhel9@sha256:d3920d5a2ed229da22f73d42090df015320e4e658959e2a6b55208e86725f4a8
container-native-virtualization/mtq-operator-rhel9@sha256:710a918d2e94e4206db8543af27a400d66781c7cf14d806197a0beae03702472
container-native-virtualization/multus-dynamic-networks-rhel9@sha256:f28ba0508523f060a321ef5c5103b8a1c34103c2c00867dfbbfa3e35259727e5
container-native-virtualization/ovs-cni-plugin-rhel9@sha256:991661d27fb201ad7ff87024b5acf9a5a3bfe85eb56efbe0f5b1a70516a67c4e
container-native-virtualization/pr-helper-rhel9@sha256:64219f95a05a6d542f40cd3b76a9f70d000d0ee85d23b342c7ea9e2977e14dd8
container-native-virtualization/virt-api-rhel9@sha256:a8ffc4436985f107b893eec058febc286e5273fbc82f033878829cb4e8fc97b4
container-native-virtualization/virt-artifacts-server-rhel9@sha256:b275ba87cb7f84ba4171b45ad784b5065ff5242f1040a5d377120a4c0e526b68
container-native-virtualization/virt-cdi-apiserver-rhel9@sha256:ef217d3459d9eb9ae5fa19f6baa105006e52d93541d35802a4271bef32b700ca
container-native-virtualization/virt-cdi-cloner-rhel9@sha256:7f72b2ce080793c5a8b37640f32ccdac537e13fabcd7c95f89bb824aee04aee9
container-native-virtualization/virt-cdi-controller-rhel9@sha256:c2d901024f6d153666381391a5cc36ba13b7145f5432385b3c6bc8070b1f5c1e
container-native-virtualization/virt-cdi-importer-rhel9@sha256:41ee5a40f70e41a407e8b431eaacafc4ff2644f321b1e6a14093ffddf08be211
container-native-virtualization/virt-cdi-operator-rhel9@sha256:a76fe0b13bfdbd9c8f5f083ce119d6b5da9cb221883d83b8484d914cd1b0cd46
container-native-virtualization/virt-cdi-uploadproxy-rhel9@sha256:7084c2245c7b620f5854b589d8b66e6e45d0d2ced00df0eb745e064685e1efe6
container-native-virtualization/virt-cdi-uploadserver-rhel9@sha256:2d9a998c9d6092e002c803bdd410c8a4fec6bf89e8e9373c050728c8bb4c5ab7
container-native-virtualization/virt-controller-rhel9@sha256:da96b63778745c6ce7b1d4451ceb2f9d8d81ae0884bd8c3e3d88f6a51dee9bd7
container-native-virtualization/virt-exportproxy-rhel9@sha256:19c51e43f9d151b93709f4fb08c4e420994bfd3bf26ada22f8f0eb0c28d4f196
container-native-virtualization/virt-exportserver-rhel9@sha256:02e276071d7652ff6de5bdad69cdf1d948ea2fd388e77ed3351d004b49ed7e07
container-native-virtualization/virt-handler-rhel9@sha256:9ccb0795d813162f11e60a9147149686738a33cddf6a0767a6727b1ab8884bf0
container-native-virtualization/virt-launcher-rhel9@sha256:de48f0ed447bc04b7c1494c2f4532b1d805837b126a6641e30eb35eee6198b48
container-native-virtualization/virt-operator-rhel9@sha256:5868b81c167118ba1bfee450fb057c3eca756031ddad4ef8471ff46da58f1e12
container-native-virtualization/virtio-win-rhel9@sha256:1e33cf22ce1a4b37ad8c2ceac4b068792793bca6b86bb8cfbdb281937fd174b5
container-native-virtualization/vm-console-proxy-rhel9@sha256:b133beebc86c87c37504fdfd142645921942ae8c52a232857c90c82054ee4ca3
container-native-virtualization/vm-network-latency-checkup-rhel9@sha256:27d75636884ca61fa0d5b753a4de9c960406293c3ae5c06abf3bedb4982a5b11

x86_64

container-native-virtualization/bridge-marker-rhel9@sha256:4227bfb6100fcec336ea1a8034f1aecb0861d07d26ebf9487a4a145a9df50b53
container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:775f9b9ad0ae569a9140e4a7a05c22b184573b5b463036dbc86fd4f2c4a25c78
container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:00d566b33cf6ed77bbcb7799bcedc027fc27325a2c9bcba0b570e43567154d6e
container-native-virtualization/cnv-must-gather-rhel9@sha256:e38828943ceff82ace62760df8cb76b8f54201d335bcf20c8a401ba51aee9790
container-native-virtualization/hco-bundle-registry-rhel9@sha256:74a9c0ab80a851f5784e2a6e5d4a51b9f43e2d2c7e8efc732b19b72b2e6352a7
container-native-virtualization/hostpath-csi-driver-rhel9@sha256:c0b66babecdd830e944e991f331bafb104cc5c203028a12088004dd8eeb0c8d9
container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:f7fe1178a205441b0642baca5d9c6a26d8dcf2f515930cfa6ee5975ca14b3a48
container-native-virtualization/hostpath-provisioner-rhel9@sha256:0a51c4d032a032f5bb27249dd3eed8f20e09301740d4b69020d8803eb40f840b
container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:a9d8563a8b104ee29a860d788dc2c2d9a8cc74255261d93bd7fe4e92d3b03fe6
container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:7433a3efdf8cacdac903228815f33f5cc4bee706b1328ab9635e206474199e6f
container-native-virtualization/kubemacpool-rhel9@sha256:ccac3c377544f9bc8c89a1260bf24b9ee8d4d2d0c857a76188db556831a856bb
container-native-virtualization/kubesecondarydns-rhel9@sha256:dde5f89908f70c742e9461cf19d98b1482834eb2b3dad3f5b838df5054b39181
container-native-virtualization/kubevirt-apiserver-proxy-rhel9@sha256:4308ce352c73fb1f0df923a57f4b949ea97e940310694a7e7b569e217bef6fbb
container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:0e6f4edef8b0ccecb3f638f664febe5443e5281c1b6b79894215e67240cfac46
container-native-virtualization/kubevirt-dpdk-checkup-rhel9@sha256:d2c70db580c6610bdbf1420c831b7aef658fa1d64938bfdd366d5fa493d2c04a
container-native-virtualization/kubevirt-ssp-operator-rhel9@sha256:2e3979851f3b32c869de3e0bf1148abb859451868a04fd7f33bd6ea34f45a250
container-native-virtualization/kubevirt-tekton-tasks-create-datavolume-rhel9@sha256:87615f0c6d8f1d509d6bfe330d4d671008bb83ab6555887a7d510fd13db85c6d
container-native-virtualization/kubevirt-tekton-tasks-disk-virt-customize-rhel9@sha256:ea682d53999b5e49f68b32007af35e24271a149ed392c2bea31218242cc86e05
container-native-virtualization/kubevirt-template-validator-rhel9@sha256:beeeee2fc3073a0e02a7cb1f87660c799deeb9fcdb1702bf870fd1934469af50
container-native-virtualization/libguestfs-tools-rhel9@sha256:f840943da632c85536faea8e62c3faedae113f539af46b17641dd84fcb0cccb8
container-native-virtualization/mtq-controller-rhel9@sha256:8e4b0467ad06adbfc4f03421025d00b9c1ac0d2d9a7552a46f66588d1eb35a18
container-native-virtualization/mtq-lock-server-rhel9@sha256:fc7a1a6c05fc355a4694ed98978aa2a110615413ac7117810a7bf8ca3a692a79
container-native-virtualization/mtq-operator-rhel9@sha256:3b9a11d2be3ede19dd4addba9a02cf13236f7602f89b7ccbc965a7cc0e4e2ac5
container-native-virtualization/multus-dynamic-networks-rhel9@sha256:8b429939dbe346b24020dbbd68e87379651b9282fca85c7fe583ded826c0edaa
container-native-virtualization/ovs-cni-plugin-rhel9@sha256:344b37d60fa9eb6cc5d45ba9def06eff5ddb88460aee49e3fe77a5043e7b78c5
container-native-virtualization/pr-helper-rhel9@sha256:5f3e87cd55b19cc8ae2884513f882e8e62bc9d981ff5282bc995b5822d0f7799
container-native-virtualization/virt-api-rhel9@sha256:ed25474a822ec4fa6d944888333320e7175833619e262ec06e35efd69f9eacee
container-native-virtualization/virt-artifacts-server-rhel9@sha256:cbf516049f392bb6260e7c50e1c7687ca5a65c983485d45470957e7d13e7ec84
container-native-virtualization/virt-cdi-apiserver-rhel9@sha256:4e150aacdf1351cfc7600ef7d7f8df9f58d7e6fec2ec48a50dda579470ff0a61
container-native-virtualization/virt-cdi-cloner-rhel9@sha256:2c6b51be73cac25c2732cb124caeb256bb3febc3693bd556deb2a0d155b08082
container-native-virtualization/virt-cdi-controller-rhel9@sha256:7fd39c97dbc36af9f0facb6c571dcd9c2352bee5a893d690b0fe6b08ca43aa77
container-native-virtualization/virt-cdi-importer-rhel9@sha256:e98160583d1138cce8b18a51995ac413577f8314ba6c08cfeceaa830590e676e
container-native-virtualization/virt-cdi-operator-rhel9@sha256:3e89a5f69f2de311ab4fab7bb50adc8bb7f558efe45b84b9344b776189bd9978
container-native-virtualization/virt-cdi-uploadproxy-rhel9@sha256:e43e3031150ab722542db845aad339f925725ef6c1770119daa7f28579bc4474
container-native-virtualization/virt-cdi-uploadserver-rhel9@sha256:8b923c77cb108be1c67a119a601f9628c7ea788bd7946a5a523239b3fffb40ea
container-native-virtualization/virt-controller-rhel9@sha256:a3005035973b8e81c43bfb305d061f9a6adbacc8ef0abb4c0d456f872b60bb57
container-native-virtualization/virt-exportproxy-rhel9@sha256:cad32e4fd7b6155645e698765a280fdf7038eef58cf29afb902c15d3c987791f
container-native-virtualization/virt-exportserver-rhel9@sha256:13be9ba139857db816e44dc9d076e68ee18f42e9431978bf787df9108957b369
container-native-virtualization/virt-handler-rhel9@sha256:fae61492eda528d968bcd1568fec3f697832ab4baf645824b8402021575330fc
container-native-virtualization/virt-launcher-rhel9@sha256:917a580de46b63dd5cbc364d65bf343195801cf779c7d7e381a88367ea286ad2
container-native-virtualization/virt-operator-rhel9@sha256:0a96121b2b588346bfceaf1aa403afd8658d31f5990175bc5c8fc943d99d66cc
container-native-virtualization/virtio-win-rhel9@sha256:9e4ff4cb81b246f0476ab7f300948223208b4c5e43e764a95830c0a2aca700f8
container-native-virtualization/vm-console-proxy-rhel9@sha256:cc07c875e19a1b5b41e6337c8fb3f4f96ecfff3d4ed3c05f39fabeb14b37aad2
container-native-virtualization/vm-network-latency-checkup-rhel9@sha256:d029dbfc1677621c536c3bdb366fb0952571bfd7f34461289e8dfdab2a0acb55

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility