Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:1241 - Security Advisory
Issued:
2025-02-13
Updated:
2025-02-13

RHSA-2025:1241 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: OpenShift Container Platform 4.12.73 security and extras update

Type/Severity

Security Advisory: Moderate

Topic

Red Hat OpenShift Container Platform release 4.12.73 is now available with updates to packages and images that fix several bugs.

This release includes a security update for Red Hat OpenShift Container Platform 4.12.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.12.73. See the following advisory for the container images for this release:

https://access.redhat.com/errata/RHSA-2025:1242

Security Fix(es):

  • jinja2: Jinja has a sandbox breakout through indirect reference to format

method (CVE-2024-56326)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating_a_cluster/updating-cluster-cli.html

Solution

For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html

Affected Products

  • Red Hat OpenShift Container Platform 4.12 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform 4.12 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.12 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.12 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.12 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.12 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.12 for RHEL 9 aarch64
  • Red Hat OpenShift Container Platform for ARM 64 4.12 for RHEL 8 aarch64

Fixes

  • BZ - 2333856 - CVE-2024-56326 jinja2: Jinja has a sandbox breakout through indirect reference to format method

CVEs

  • CVE-2024-12085
  • CVE-2024-56326

References

  • https://access.redhat.com/security/updates/classification/#moderate

x86_64

openshift4/cloud-event-proxy-rhel8@sha256:b8ea13af0ca7e52b10f133c749e5a58390135348933771581df3a4cca6f013bd
openshift4/ose-cloud-event-proxy-rhel8@sha256:b8ea13af0ca7e52b10f133c749e5a58390135348933771581df3a4cca6f013bd
openshift4/ose-cloud-event-proxy@sha256:b8ea13af0ca7e52b10f133c749e5a58390135348933771581df3a4cca6f013bd
openshift4/kubernetes-nmstate-rhel8-operator@sha256:d9a3de8a5687c8323dccfe4efd6ff51b9b3fd8f60a91e83e5ead75ac83834122
openshift4/metallb-rhel8-operator@sha256:8e7714ef606d603c03383b53f5581de648f52614b85b445a8309606386d14970
openshift4/ose-ansible-operator@sha256:6ce836d2edd59115de5effcfeae86c3a2c71194cfe8c5e966049f7534c7739ee
openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:6767351952682d50232a964824ad4232c796cf9d9b439853823963e1d5b55e7b
openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:abaabf053be0766126d2c84c00c868bc40aad80d73da5d95ea981216751f4ec8
openshift4/ose-cluster-capacity@sha256:6a32f1fa6072b2e0d7f87d490bf9beaa242881fc76fa8d6f82717c2d7ab38998
openshift4/ose-cluster-kube-descheduler-operator@sha256:dadf519c39db8eaca3ae19a7b6b91c22a165dff270b9570af5fd291fa4a47ca7
openshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:dadf519c39db8eaca3ae19a7b6b91c22a165dff270b9570af5fd291fa4a47ca7
openshift4/ose-cluster-nfd-operator@sha256:6bcf297c78bef539449faf9f14ef1a1aad31243e980345fd4fda1cacafed5343
openshift4/ose-clusterresourceoverride-rhel8@sha256:bd8759cd6c29f80ffdc77ddebd6d665915ab8ea1b70cd18bcee9452310648bdb
openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:f345077acab537ded71dc4cb86b7fec95a493759dd13138d35d144bb47e889ab
openshift4/ose-contour-rhel8@sha256:63758878dda70562a07a3f49765fbe9e0d6e1b619b73f6b4d7427467f7fc4254
openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:3896c25a9de8f94b7330ec6b58808e84d146b183f837522f83e250f4d79cb8a8
openshift4/ose-egress-dns-proxy@sha256:e8b1f0c5c193cd7347731e3b3cc0e68ebb70b273bbab95baf09fd6503b6f1ba9
openshift4/ose-egress-http-proxy@sha256:f9f090903487d0d44ac8432124c82081c8005a8b3b2e7d617fcbe045649937e4
openshift4/ose-egress-router@sha256:01e63995414df066a434a31737e274824bca95bb250f5bb70f0a1cd7b6a31953
openshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:b313de17a7db17e587270e172b24122a3bb614fc64675bdb04b1f637ebff8f48
openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:dfcc5a6f1e997d0e16f93d7ea244e7a1a50a84df66a9c0e3a5e8b9aef08bc697
openshift4/ose-helm-operator@sha256:16c739f30c876157057b21135118399cd5b5a27fa809358c697df1607fcb89aa
openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:032fabec4d3bc7073800aae994278f9f5f2514a0cdc7961813c4d11cf37eb025
openshift4/ose-local-storage-diskmaker@sha256:ff917ee18bd3101a746c71a8d29d86bf7ec61295a86ff8fadf66e771a8332a0f
openshift4/ose-local-storage-mustgather-rhel8@sha256:bb876e7b9319c55b259f4eabd81978b7396a99dfc696454695c6459b65e39bec
openshift4/ose-local-storage-operator@sha256:9e887a3c00520d68e2206af7fffd0cb81d872e40e57e519829377d88f3bd169e
openshift4/ose-node-feature-discovery@sha256:47a9f9b721bcd2a622b011773288126e229330542767655359392526b8678369
openshift4/ose-operator-sdk-rhel8@sha256:350b1d292b2ac40077cb405ba8f1de04d545d8e549c98fd017d00ab89a76ffdc
openshift4/ose-ptp@sha256:803fd085eae81adf14fd31e914f34aae89925342ca067e50900b1af27b0e0bb5
openshift4/ose-ptp-operator@sha256:54ececa36ef9491647773fd9c21ab4d7daa92c0409a8833218ea9668e1c63179
openshift4/ose-sriov-cni@sha256:bf693959716549d2f1367f2cb93f5180b8a8c2603407169fcee75aa8bddadb7b
openshift4/ose-sriov-dp-admission-controller@sha256:d48325e6cf96fbb476067de111e25bdc750d602f08283bf966a842a04753c4b4
openshift4/ose-sriov-infiniband-cni@sha256:5a9429fa2b0da2a0a4394c0b6d03ba6b438599bee8d4639915e8b2e9372b7420
openshift4/ose-sriov-network-config-daemon@sha256:1ed6c9c79a72483611ca1a399dbf875468966eaf049f154283e64e9d7ef5fa33
openshift4/ose-sriov-network-device-plugin@sha256:6631bdb0024b5c48c3ce003aa5d0bebefd94d1d083520d8f2856467d0f8b2c25
openshift4/ose-sriov-network-operator@sha256:0d9ea539470a7f83c471a232554d9474b223f4ddd78f80dbc75acf2ccfd2b97e
openshift4/ose-sriov-network-webhook@sha256:cc1ea4db5ea3760e5f93b0be3985c4bea58303e51ee5951fc9f7ba8fab2503e0
openshift4/ose-vertical-pod-autoscaler-rhel8@sha256:b8ae092fb760ead1ca9a23fa9f23fc11dee4e05d1028b6e1ab323875a4639ab9
openshift4/ose-vertical-pod-autoscaler-rhel8-operator@sha256:79a076dc2ec9821812ce35a9fdb72978317d8a3c2b5d4b384a7815a0f89394fa

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility