Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:0079 - Security Advisory
Issued:
2025-01-08
Updated:
2025-01-08

RHSA-2025:0079 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: Red Hat OpenShift Data Foundation 4.17.2 Bug Fix Update

Type/Severity

Security Advisory: Important

Topic

Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.17.2 on Red Hat Enterprise Linux 9 from Red Hat Container Registry.

Description

Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API.

Security Fix(es) from Bugzilla:

  • dompurify: DOMPurify vulnerable to tampering by prototype pollution (CVE-2024-48910)
  • express: Improper Input Handling in Express Redirects (CVE-2024-43796)
  • send: Code Execution Vulnerability in Send Library (CVE-2024-43799)
  • serve-static: Improper Sanitization in serve-static (CVE-2024-43800)
  • nanoid: nanoid mishandles non-integer values (CVE-2024-55565)
  • cross-spawn: regular expression denial of service (CVE-2024-21538)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Data Foundation 4 for RHEL 9 x86_64
  • Red Hat OpenShift Data Foundation for IBM Power, little endian 4 for RHEL 9 ppc64le
  • Red Hat OpenShift Data Foundation for IBM Z and LinuxONE 4 for RHEL 9 s390x
  • Red Hat OpenShift Data Foundation for RHEL 9 ARM 4 aarch64

Fixes

  • BZ - 2311152 - CVE-2024-43796 express: Improper Input Handling in Express Redirects
  • BZ - 2311153 - CVE-2024-43799 send: Code Execution Vulnerability in Send Library
  • BZ - 2311154 - CVE-2024-43800 serve-static: Improper Sanitization in serve-static
  • BZ - 2322949 - CVE-2024-48910 dompurify: DOMPurify vulnerable to tampering by prototype pollution
  • BZ - 2324550 - CVE-2024-21538 cross-spawn: regular expression denial of service
  • BZ - 2331063 - CVE-2024-55565 nanoid: nanoid mishandles non-integer values

CVEs

  • CVE-2024-9287
  • CVE-2024-11168
  • CVE-2024-21538
  • CVE-2024-43796
  • CVE-2024-43799
  • CVE-2024-43800
  • CVE-2024-48910
  • CVE-2024-55565

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

odf4/cephcsi-rhel9-operator@sha256:2a35f5ba5c9ad6106bae6988671f0025d4450868ae705714b791be081ecc5495
odf4/mcg-core-rhel9@sha256:4ac2448215ef79cbfaa2be5d2d15552e7545f686e08f221f734fae87ed2d719b
odf4/mcg-rhel9-operator@sha256:944698a0fc7e6486d8f5852e41d192f4b2a82d0b26dde20727369cf996cdcb28
odf4/ocs-client-rhel9-operator@sha256:6d43d5dd3ba338fed7829368e5954bbac0525d5b4d30bb2ff7e38114c0933fa5
odf4/ocs-rhel9-operator@sha256:d93fc186a24ac45a773cb5e99357e3bc6ed2cc74859c4012b75aac2fa28bf8f0
odf4/odf-cli-rhel9@sha256:e2e441efe3dc5cc2edb68bb05d86ae018a9c5ad6e26e775c1f52543b499139ff
odf4/odf-csi-addons-rhel9-operator@sha256:c34463cfce14762c0b88b6dc8cc96c311894677900c078e667d5bc1ab69d6afc
odf4/odf-csi-addons-sidecar-rhel9@sha256:6e1ed854de146e1318f62158ea9c9be7157d51edbdeb595de80f12175ae09014
odf4/odf-multicluster-rhel9-operator@sha256:7bac23f67cdc1028dca5c88bb37e8f43a6a0dbb770915d9177dc720e1da7b243
odf4/odf-must-gather-rhel9@sha256:27f4b9b291291755100a8aa4e7f81bd4fc0ed49029a87b05e2aa9f89720a8e2e
odf4/odf-rhel9-operator@sha256:732fbdb173ae4b3ebc3969fa6b0452a8e111fbc207c8e8000fa6ac07e5f59f32
odf4/odr-rhel9-operator@sha256:c42a54ec5d88f8027299c3feecdf98d59fec6873209140859d4fbb67c0a9ef1e

ppc64le

odf4/cephcsi-operator-bundle@sha256:fc991288aef78334dc19380cc5f80492bb25bee7c8fda79e552c384db064b220
odf4/cephcsi-rhel9@sha256:8f32d658563f095fe196f4e23be66f5f5afd48a97bf929c35bc11eb0db1d5226
odf4/cephcsi-rhel9-operator@sha256:bffa592135687eef55d95e8b88beb6deda2015e8da86f03c471dfdbb105fca40
odf4/mcg-core-rhel9@sha256:8edd7771c1c6685766bce549ba9b43d851935e7241b3b0ada27f85943b6b7cc0
odf4/mcg-operator-bundle@sha256:268e42ceb31e7d3e404fe1789e00456a23d47aff83fdc8a6e2f33b611f74a1d3
odf4/mcg-rhel9-operator@sha256:57ca5c5a78fb55760a0ff22ffcaae42bfd185ff73536a710e6297b5cbf8de6b3
odf4/ocs-client-console-rhel9@sha256:79b15f4f324f4a1013a6b0099e166313c1aef9d6d63bb5ef76969d59b8c92782
odf4/ocs-client-operator-bundle@sha256:78386fb2e4d17772ca03331f85bc9ee13b9b60721dfcb62e75cad59f2845991a
odf4/ocs-client-rhel9-operator@sha256:e87a8191dbf0f71f04798c5ca8516350ab816f332c064e1e75c54e75bd234554
odf4/ocs-metrics-exporter-rhel9@sha256:1a79e34315fdb8daa5d2819b780a7f6d6aedb2a485e09f72606ccf75a93d5cb1
odf4/ocs-operator-bundle@sha256:5d2722ef7348f482a7435210afc4563ddc1d01c2e688bfc8fb6428d1d4d0e555
odf4/ocs-rhel9-operator@sha256:81293f970716ef414db5926e94ac8b95a3d31fccb66645e8a971461e27bdef8d
odf4/odf-cli-rhel9@sha256:69398d29aa1dd6ef4ebd7077109997b9fd38ecf26beec724c4a5f16e2978494a
odf4/odf-console-rhel9@sha256:e32a1498297569e78c5b16d4a00418ea54331be09ec162676da22d9005d8f2ff
odf4/odf-cosi-sidecar-rhel9@sha256:06849a3ffb5eaa18ebe10e273cc276448bf6bd5237a86822e7b0519d5be8f6e9
odf4/odf-csi-addons-operator-bundle@sha256:769a356e498838626eba728a90810934a382d037e95346397083eb56d149da5b
odf4/odf-csi-addons-rhel9-operator@sha256:004abd3e88b58cabf5e3da007bc1be414b2c7cf1f0089ad4a9b8647b9f9925af
odf4/odf-csi-addons-sidecar-rhel9@sha256:8a26d68bcb9263f78f01cc317f52dca9494e9e719f7856db10793ba498acccc2
odf4/odf-multicluster-console-rhel9@sha256:4cb7cf08ed562f95b219999fc991b64ea2071fd1932549b89727301da582766c
odf4/odf-multicluster-operator-bundle@sha256:d5ce9c74d3c5680d4e6404bd770bfe5e19d287c5e1e7a115d1d6e9257bc4e7e4
odf4/odf-multicluster-rhel9-operator@sha256:062afe0ee7fb2e65f8e4975093284a63cf68bb205ebeb67f1be10595859530ef
odf4/odf-must-gather-rhel9@sha256:adf85e346b47a68696a7553587a67d3b57f45f971dd65f3c9dd84060a607d582
odf4/odf-operator-bundle@sha256:b79630e1acd2981966524e17b7d98e58f40eb18b7adca11a177496e3e82547b7
odf4/odf-prometheus-operator-bundle@sha256:c9cca432420ddfc450ccc1ae9bc751cf5c79f64f1140b70e14eda6849ab046d9
odf4/odf-rhel9-operator@sha256:7d9d966466bea941d2c040bc6db5b2cc64d68d16bca9d51d6d8da91ff3530263
odf4/odr-cluster-operator-bundle@sha256:ddd2feca5ff71e8379b60fdea17d02c2d67b1cbdb4fcd1c7bb408d38f0ef739e
odf4/odr-hub-operator-bundle@sha256:a38d1461acd190a3083905beff068f256afd3c81354ed6c39b93b3e17b2831df
odf4/odr-recipe-operator-bundle@sha256:66c9d2fc679ee685ded21ec3f2d18d1e828fd1c58548d29f367f25ebacd1a859
odf4/odr-rhel9-operator@sha256:b1798bebd8a861ed325005d5fce44c0ece05a0e3ed0ed574a09c766d3e452b97
odf4/rook-ceph-operator-bundle@sha256:1fa4d0f267f9ee5d94aa62c14af4df147eb03c99488be68a90eacb584dc8173b
odf4/rook-ceph-rhel9-operator@sha256:387a9e40f579c6d77b627cca967a5284fe28876cbf90e1864395f4d5ab39e755

s390x

odf4/cephcsi-operator-bundle@sha256:84ee4e907361648d1249c9333e7af761708e5ce3a244f8963d71bd6f76a70439
odf4/cephcsi-rhel9@sha256:5ed6e1b53d317f77a578a6e8786d2eab02d47995ccc093df4a11316ed47e6c87
odf4/cephcsi-rhel9-operator@sha256:e0182b77bb51605b9cd77322ad8a61bb9cf74eb84d5ceef512330b7138396fee
odf4/mcg-core-rhel9@sha256:ac79fb6e7346571cd547f28a06b3f9160ebfa2167df8ae4666bee118fe23c9f7
odf4/mcg-operator-bundle@sha256:3876b8d184301508d72ea48ca5d3b764776b3de8791a241478f5eff9d6b81b06
odf4/mcg-rhel9-operator@sha256:1f07db58c965bd7c5e817d6585318934a34ea8ab7f880faac0ba27e2aed5d6c8
odf4/ocs-client-console-rhel9@sha256:83b57f2c76262e933fb1c80acb6a9d6b4c12e300171335c92f676ee47972490e
odf4/ocs-client-operator-bundle@sha256:31a9db5567859cd5c57a7e327f6027da90a8b6c2f517be1c69e5bcce7b2815df
odf4/ocs-client-rhel9-operator@sha256:e7ac257790edfabe9df5d8ab693e1ef77809f3b7c4c725d43ad54b1b88866451
odf4/ocs-metrics-exporter-rhel9@sha256:b60f4d0fc3b68412584c5b2abd81a51acb61a68eb288f5ae619d8f6f5b5a45cb
odf4/ocs-operator-bundle@sha256:b5fd9d2184995f5774db40cd9a698d8cc4c36ea5f8428e30f5faca7a1846b2ba
odf4/ocs-rhel9-operator@sha256:edd97f9ca1a010cfb9fc5353794a109945fb49e535665de3d299e8944680c543
odf4/odf-cli-rhel9@sha256:6fef3430c622fd33acfc5a2595c4403b69a956f69f04252de4d5e3d96ba7c749
odf4/odf-console-rhel9@sha256:371614640a15bdc8bdd308e7125146bc9621ea73d0136979d29e53a412b1f3ac
odf4/odf-cosi-sidecar-rhel9@sha256:6611c1cb7e3ee5eb890941b305049550c89962b83753e3fe561a90f162c2754f
odf4/odf-csi-addons-operator-bundle@sha256:6daba9dc88608ec1368263dec15b4d87a5d8c39ddda9e95871fd73c23d50f7cd
odf4/odf-csi-addons-rhel9-operator@sha256:b7db3130f6084d36f4c91cd6da5e867e8db4843ee193fd03e79ced13aa6da142
odf4/odf-csi-addons-sidecar-rhel9@sha256:48309b5e97bcd14bcb5a859e00e647b198f43402389eddb20bf52df2a914f74d
odf4/odf-multicluster-console-rhel9@sha256:95c3b19345244d183b171239e8f198fc3f64874b1e08a42fa205cd05971532ab
odf4/odf-multicluster-operator-bundle@sha256:6b13a813b692b7d32ef99463b10d9b0424be2e2887c6b2ba57eb6bde08664b65
odf4/odf-multicluster-rhel9-operator@sha256:1fbf0917646546de8649716eb9ba6abd60c3781540593b2fcb72094adeef1906
odf4/odf-must-gather-rhel9@sha256:32b7301060a96868826caffd9038331d452240a8683b8afdbb0716d033b18cde
odf4/odf-operator-bundle@sha256:d70108793a296ccff688f6d0d89658f1a3f325396e0ff262ad12bdc8f4600990
odf4/odf-prometheus-operator-bundle@sha256:5971a75386afbdf8f419f93ec95545a3e5e7bc53f3e10abdbf93fb17c17fb359
odf4/odf-rhel9-operator@sha256:0937c6d8713a000d816c4bbaf1f6e0f37250e1d71df5bb8c3f7e8f60715481e4
odf4/odr-cluster-operator-bundle@sha256:9d8dba6f06018c3ba106cf1dd1a2ed23139e1159248f04b6ddad1337df743f6a
odf4/odr-hub-operator-bundle@sha256:a91bfd587473ed678548bf8fa6363d7e670417125dac9b99e950ff676b450c2e
odf4/odr-recipe-operator-bundle@sha256:d2a9c5f97f1dac2cc4b0015a560d186c5779585d056828a0949b713dba55d409
odf4/odr-rhel9-operator@sha256:9a97ef0c1af95a782f7f3db988a9e651191beba9c225a84b64b8a2d12d192790
odf4/rook-ceph-operator-bundle@sha256:16d5dacdaba34f861831f89a6f7d7a9a10d9d2c8d0af8dcc09058ca770de2ca7
odf4/rook-ceph-rhel9-operator@sha256:951faa6961b0623e7f3d8daf15c397cfb6cebc13e1c28b101e2d99df06fa8317

x86_64

odf4/cephcsi-operator-bundle@sha256:cc7efc137a03e402c8ce570818ff5d285bd9d7a3b7e198d8b7757b9a3e5908a1
odf4/cephcsi-rhel9@sha256:d54fd1a2345699a240a7d65d09ac7eb6da8df7d582fe0bbef309c206427d4958
odf4/cephcsi-rhel9-operator@sha256:54f6bf8b64afc3d4dd2e6ea12e72ce06cbab86ec507c1252cc34585cf3ee3fcb
odf4/mcg-core-rhel9@sha256:162aeae7c3910ed7404e0ef7d881188a5e5f58f2f2a2debe22bb16f9638eb0aa
odf4/mcg-operator-bundle@sha256:4fed3aaad75c98bd90cdbd81c67d590ee86dadf64aea6e93d0a1e48e6ef273c7
odf4/mcg-rhel9-operator@sha256:50e47948901795bd0e3bc7a828266a1b4d0e958fdfaf8dcfd85f805853f63e41
odf4/ocs-client-console-rhel9@sha256:be15a41d01476fac0800d17a923debc8195a9b5149436c7ed6aa28547a699604
odf4/ocs-client-operator-bundle@sha256:b95a20c8dfc09cb0ed7f2a3639f279bd09d7f306a28730e092e899adfb62e36a
odf4/ocs-client-rhel9-operator@sha256:7330de229659f3f60022f24c6f2eaf519bd94a6ba1c943cc10b5225525c16fc4
odf4/ocs-metrics-exporter-rhel9@sha256:58b66861f4d463433c1af23bd61bc497009f8dc3e997102a93343463baade755
odf4/ocs-operator-bundle@sha256:4fcc5659e079d6ed2333a81a1c28748e54316f1fb0cdbaaa4c4bf782b2b7c2a3
odf4/ocs-rhel9-operator@sha256:9e3bcb974ad550219ae0111294803795bcf464d31aa977693debd76349d123e2
odf4/odf-cli-rhel9@sha256:bd5a6daaaa0d540c43cb02f56fd1040ccac56e20a7195ea6282f60899808fcd0
odf4/odf-console-rhel9@sha256:6366316db946c5479d3dd52a2748fd3b0950a9e9b65cc4ba9b830ae1cd62a360
odf4/odf-cosi-sidecar-rhel9@sha256:82a3258ccf480232dfc55b5ee1e038934b9762f8060c07234eb360c52020025c
odf4/odf-csi-addons-operator-bundle@sha256:e274d5590ae73f91e74adb1018fce6c25c618c91cffdf6e8c8cafeaf60f04ea8
odf4/odf-csi-addons-rhel9-operator@sha256:22ace45fd7fe7f01b4435af4aa361d18498f772a7f03e772841d8f6b61d4c514
odf4/odf-csi-addons-sidecar-rhel9@sha256:848ccb7443b75b79d453a1c67817a360f26307e976ac14366af46ea47f7a77b6
odf4/odf-multicluster-console-rhel9@sha256:78dbbbf7ba31cad5a13b10fd3ca65ba940fd7348ab6d600fd370d0b56eb123e1
odf4/odf-multicluster-operator-bundle@sha256:af7d9750acf61408f6c1471381114d37cdaeae9c91f2f815200f60d9d4891fa9
odf4/odf-multicluster-rhel9-operator@sha256:ed3897a34c2f0e644efe0ca7d5ad1412f60bc51036a70da5b557d978f5994a87
odf4/odf-must-gather-rhel9@sha256:4223507b8a236d66bc19dcdd4cb7d6c138993e76aac652fa70f92cb73f3db368
odf4/odf-operator-bundle@sha256:4c9f227e6aec7f6039c74826c5f6b531cc6f7aa85c3f112f6351f6996ec6ed1b
odf4/odf-prometheus-operator-bundle@sha256:2a9b4aac9a0026c8b882245668f6400e34dee16afe446c5392b9bbf99a62169f
odf4/odf-rhel9-operator@sha256:9b2e9617b03fb406f82a5b2b82d365df0a739d0ad40c0d468a61ce31589f65c2
odf4/odr-cluster-operator-bundle@sha256:a34ef8d6c8531bf2b10083c4c462e08b52ac26e99e27d1245714834f80593706
odf4/odr-hub-operator-bundle@sha256:138a6f701943fccc0ff3ef2009b247c9fcda7a929a8157f6c751276a82019f10
odf4/odr-recipe-operator-bundle@sha256:668ed1a51b052531eaff83aebb43a98f71f1294ba7ec574264d43cb9f9145688
odf4/odr-rhel9-operator@sha256:33b6d37920088d60404bb43fe5cce095fda53b11632affaa3e04bc25c90d74ed
odf4/rook-ceph-operator-bundle@sha256:3ab58ab02668d7bdd48e6ae1aea760dc955d45e426609a1b177635f377e1921d
odf4/rook-ceph-rhel9-operator@sha256:e3257d9951ce1cf0f2abcf8edeedcf5468567ba61e0e9b127e4a2edf2c44ca8d

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility