Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:4269 - Security Advisory
Issued:
2024-07-02
Updated:
2024-07-02

RHSA-2024:4269 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: OpenShift Virtualization 4.12.12 Images security update

Type/Severity

Security Advisory: Moderate

Topic

Red Hat OpenShift Virtualization release 4.12.12 is now available with updates to packages and images that fix several bugs and add enhancements.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform.

This advisory contains OpenShift Virtualization 4.12.12 images.

Security Fix(es):

  • axios: exposure of confidential data stored in cookies (CVE-2023-45857)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Container Native Virtualization 4.12 for RHEL 8 x86_64

Fixes

  • BZ - 2248979 - CVE-2023-45857 axios: exposure of confidential data stored in cookies
  • CNV-41510 - [4.12] CDIStorageProfilesIncomplete caused Openshift Virtualization operator status go degraded
  • CNV-41952 - [4.12] Missing storageprofile setting for infinidat csi driver

CVEs

  • CVE-2020-0256
  • CVE-2021-0308
  • CVE-2021-25220
  • CVE-2022-2795
  • CVE-2022-3094
  • CVE-2022-24795
  • CVE-2022-48624
  • CVE-2023-4408
  • CVE-2023-6004
  • CVE-2023-6597
  • CVE-2023-6918
  • CVE-2023-7008
  • CVE-2023-33460
  • CVE-2023-45230
  • CVE-2023-45234
  • CVE-2023-45857
  • CVE-2023-50387
  • CVE-2023-50868
  • CVE-2023-52425
  • CVE-2024-0450
  • CVE-2024-2961
  • CVE-2024-3651
  • CVE-2024-22365
  • CVE-2024-25062
  • CVE-2024-26458
  • CVE-2024-26461
  • CVE-2024-28182
  • CVE-2024-28834
  • CVE-2024-33599
  • CVE-2024-33600
  • CVE-2024-33601
  • CVE-2024-33602

References

  • https://access.redhat.com/security/updates/classification/#moderate

x86_64

container-native-virtualization/bridge-marker@sha256:d0dda6b19805883eb6f7fd01414d9d186469b1def94a48d2e96747d228b5386a
container-native-virtualization/cluster-network-addons-operator@sha256:727e02c8a2b8b5f3c5e0cc6080ee824c0ace3ab15c16986124a10e72ee28aad0
container-native-virtualization/cnv-containernetworking-plugins@sha256:d49c2e83ddd78029aa4fd44b34d9999d9ce9e58edd8a98fd36491263c9d21428
container-native-virtualization/cnv-must-gather-rhel8@sha256:59ff3b1cddbb3bee6175483b3c75f22a52fb236b47b0284b468aa49e8a7f6d6f
container-native-virtualization/hco-bundle-registry@sha256:f1ed1de96a233518664503d0ed8496f4efa1a7092b4e1f20082a882b35c396fd
container-native-virtualization/hostpath-csi-driver@sha256:4b5b96b3c0444e67c4297fc4a9f9425f292b6ba685595a08c38d4483b56e8f54
container-native-virtualization/hostpath-provisioner-rhel8@sha256:91e35fdc8e75b64559c74b5800bf1abdc837f7ad76cbb9cde32096e0c07c4259
container-native-virtualization/hostpath-provisioner-rhel8-operator@sha256:2071baed66866393a5773b538bdca0f9c110be7c6afeb5488b3898541fbf09c5
container-native-virtualization/hyperconverged-cluster-operator@sha256:d2dba9ae9bfc12b7997f51622011a703f1b7b0e61d9e44a276e40a4561ce8fb4
container-native-virtualization/hyperconverged-cluster-webhook-rhel8@sha256:81b037f3a81b068300ebaf60d619543ba5629a66eb45b532fdcc8d4709a949a6
container-native-virtualization/kubemacpool@sha256:54c5d446dc9ab54381ef75ae10e9114e3cca1dca2c5fa09195bf37f3cf689da3
container-native-virtualization/kubevirt-console-plugin@sha256:a8b542d4876bb8b82f5a66bc0d452582b8cffb1e1d66aa2b1651612bb6041c19
container-native-virtualization/kubevirt-ssp-operator@sha256:d7925a86d8b4e5f7416e3673a3841a59629ee4183da03e2002debf31744458bc
container-native-virtualization/kubevirt-tekton-tasks-cleanup-vm@sha256:1779baece47a0e5816f3ee67e96ed99a67441b9ae7a3d73c50398e40c0a1baa0
container-native-virtualization/kubevirt-tekton-tasks-copy-template@sha256:336fea863a0a538295876cb1164d3c4c6038dd463ed38a20a97127d85f3cd004
container-native-virtualization/kubevirt-tekton-tasks-create-datavolume@sha256:57c136f41f5342dc0a20155b43435a184f4227804a436075276e38390e7ad69c
container-native-virtualization/kubevirt-tekton-tasks-create-vm-from-template@sha256:df422f53becac90e8a075048a2624a379c209b281d376059a5b9d1ef5d262903
container-native-virtualization/kubevirt-tekton-tasks-disk-virt-customize@sha256:c6644084f4584bc06e8314162090f5053d9ff2319721615407eb3e7c5415f58a
container-native-virtualization/kubevirt-tekton-tasks-disk-virt-sysprep@sha256:621f110b8c30676ed47a56089938d344a7f2708e5dc8fe168a1821af45a29959
container-native-virtualization/kubevirt-tekton-tasks-modify-vm-template@sha256:b7b41226f53d95c4abf8ecd9ddac626e4df20f6d5df963bdea5f46b90c8872c6
container-native-virtualization/kubevirt-tekton-tasks-operator@sha256:68992af891953d888e87cb998ef02997b46affb6de8ba665cddaeb7c10d6651d
container-native-virtualization/kubevirt-tekton-tasks-wait-for-vmi-status@sha256:7092d7493cb6a4f4faec294119f6be312753ed4fa6cfe0ada65fa81a233da2a3
container-native-virtualization/kubevirt-template-validator@sha256:c5427d8441f9be1fa918836af7fcab89a436c08c4f06ebdcc0f885697078ddda
container-native-virtualization/libguestfs-tools@sha256:cd5dd79471cf8339d61d0c337c6c7aa2a067209c57495e82587534b673899f0c
container-native-virtualization/ovs-cni-marker@sha256:3dc7177d76b55a699408f550e31b7b8a270066d029afe74f186e8516192d140b
container-native-virtualization/ovs-cni-plugin@sha256:eb5ecafa605a4c5d20f52cb6147253660092715241def2fe64f7222afa2ab254
container-native-virtualization/virt-api@sha256:e90c32eb92031ee1aacc50b6dd0ffbeae817c2f55deea56a415eb98c3b727935
container-native-virtualization/virt-artifacts-server@sha256:ee7c3ab336f8a5617ba930610d942bfd67f39fffec6cd7a2ab95d7f2857acd87
container-native-virtualization/virt-cdi-apiserver@sha256:019d5b88e542f88b1429534d0bccfef3252b95b4930cb8f224694ce104a19bdd
container-native-virtualization/virt-cdi-cloner@sha256:13c0401be1a5d7a057f35c892d938d0dae74da1f083b402eefd4b0ed29cad475
container-native-virtualization/virt-cdi-controller@sha256:119e0f963c9c147ca075ca466f861b5135663db109f092ed23c66ee881468086
container-native-virtualization/virt-cdi-importer@sha256:8324d439541da3938d6eb42a3615e8fae56a29bf3c28f61cc05113f6610a3931
container-native-virtualization/virt-cdi-operator@sha256:6dc55de73b78b93271a2b068e7b89d4c2ce4497df6dd668ca8b81c9bcb091be1
container-native-virtualization/virt-cdi-uploadproxy@sha256:e42a5394b2671f8a881d0687d687c45f3ac59652fc27e129e212bd5cf743a319
container-native-virtualization/virt-cdi-uploadserver@sha256:a8b28537cc2b552787a06eaca1d56b82dd81dc9c792767ef09c735cc2f128f00
container-native-virtualization/virt-controller@sha256:0e60ae73bd4e3f3ac141858887c618680e0da12956f7f11948bd720e47fdce95
container-native-virtualization/virt-exportproxy@sha256:83800c207a74a2bb73efb7cdaa5cb074fa59802cce53c22cd7c909ac9568b4a8
container-native-virtualization/virt-exportserver@sha256:361f7d2c05c75083863d35a282895ce2c0b35df7ec4b4cefd0518cd25e952879
container-native-virtualization/virt-handler@sha256:76efc33dabc0cb68f845222cc71a2b44a003c13b1b31bb0519c470747508237a
container-native-virtualization/virt-launcher@sha256:9b34bad84b6df588c97e4db9f7aaadf4e028b75b262fb5a37e3b28ef7f194730
container-native-virtualization/virt-operator@sha256:8a1c199fd369bc5db46febe8fbf1b876f2950a9c7ef42fd1ee1868693799a13c
container-native-virtualization/virtio-win@sha256:8ef5c4527ad5c65a60bd523563d59acfc14346be18e43004e49afcac91d20733
container-native-virtualization/vm-network-latency-checkup@sha256:f91b90a3b09a5097494743b93b49ec007d0263750a11df1444266f91bd3a3503

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility