- Issued:
- 2025-08-06
- Updated:
- 2025-10-15
RHSA-2025:13241 - Security Advisory
Synopsis
Logging for Red Hat OpenShift - 6.2.4
Type/Severity
Security Advisory: Moderate
Topic
Logging for Red Hat OpenShift - 6.2.4
Description
Red Hat OpenShift Logging 6.2.4 is a cluster-wide logging solution for OpenShift that collects and manages applications, infrastructure, and audit logs.
Solution
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:
https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ocp-4-18-release-notes For Red Hat OpenShift Logging 6.2, see the following instructions to apply this update:
https://docs.redhat.com/en/documentation/red_hat_openshift_logging/6.2
Fixes
- LOG-7267 - Remap error in output_logging_parse_encoding: join function failed due to non-string array items
- LOG-7280 - [Logging 6.2] Otel dataModel is enabled without the tech-preview annotation on CLF
- LOG-7303 - [release-6.2] loki-gateway does not enforce fine-grained authorization on /series endpoint
- LOG-7304 - cluster-logging.v6.2.2 missing operators.openshift.io/must-gather-image despite CSV defines must-gather image registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256@sha256 delivered in the operator bundle
- LOG-7313 - [release-6.2] Loki log based alerts for application tenant are not filtered by namespace on dev-console
- LOG-7317 - [release-6.2] Cannot create AlertingRule for infrastructure logs without specifying the namespace
- LOG-7387 - [release-6.2]clusterLogForwarder API doesn't indicate that the kafka URL should be tcp or tls
- LOG-7599 - [release-6.2] vector panic due to Timestamp out of range - cherry-pick request for vectordotdev#20780
CVEs
amd64
| registry.redhat.io/openshift-logging/cluster-logging-operator-bundle@sha256:94f256283b590b46946eb090170b62b824331c1d969102d214f04eb6537227e4 |
| registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:608316ddc84a51892641faaed478f029578c0cb817e75eeb74124ce7eb1bec94 |
| registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:335edf3dc888484de4f0487c8ae39e6671a82c0658856963201c81d46e40aa9a |
| registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:e5e63fe04cce9e2b73bf1cc7f9461f7baa1c59429a98e3198ff3c1557c85c5c3 |
| registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:5c7b36487fab2057916f542c3c008437e6ff8310df2784f40571f61681fd5653 |
| registry.redhat.io/openshift-logging/vector-rhel9@sha256:f9cad0595a63e44a56493a8b941dd81be1600b7cc842078390c7d51371067d3c |
| registry.redhat.io/openshift-logging/loki-operator-bundle@sha256:aacdf148cc6886296bdf93aacde9860626a982550321a26f608ffbad919bfb7d |
| registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:1f25d7b17d35870d97dbaa62a4cea9a000b289ae16b85e50f443d5417559f8d7 |
| registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:649e2912ab58078b4fd20d03fe0fc89d5c99676931b14e1a1ee7b200d6e95a48 |
| registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:9f7403f9b789d7c176ac9b653c496b6e5558e4918668389232f9910d18a9ab93 |
arm64
| registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:6cdb4ee58422affd7cde8305f5dfeca0c7ab766b01084013e2436a9826f0d9f0 |
| registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:ba67434d17ca507bec8c4b0e0013049b5fabacbe57348b205baa296e5454e850 |
| registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:56a5b8ddde136762e460b308bc86a8bc88c421f75a621b44c329b2e07846ff05 |
| registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:bcb933c55b3e2aff0c02b7d395ba3b42c8009488007d1bb44d5a8e828c757e16 |
| registry.redhat.io/openshift-logging/vector-rhel9@sha256:c938f67db640b4eb2ba3a64eae4b45dd0908cc6cbb8c885aba755d08c3485d9d |
| registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:c11506f25cf9d2783dd2022318d8be01a300c7dec15832824a60238975af65da |
| registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:87333626d4c666a7cd36f014d7ff000cdfc666948299de19aeab0bf42cd8a858 |
| registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:c7168687f73b13377eda2c8959a76f2b18a9bb350168942b7ed72ac23852e052 |
ppc64le
| registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:c55810ccea043b9f6fc75d5ec83ef0b9b4bdb7f4f43bf0c288b9315f611c6065 |
| registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:7287fbd3cac31f65415b17e0ccce090ec81ac3c010fdfae56ad539107239ad50 |
| registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:4e7088f7658dfe7980cae9fc1a452db1630f702624a6e19874b27fe3e1c4cb8c |
| registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:155b537c4ce287bf67efb8481dbbaf339903c3d20501b026972f24a46a9d78f0 |
| registry.redhat.io/openshift-logging/vector-rhel9@sha256:074b766f972c55577cfa1b4714b505db176e20217ce9d2cf007335b4930fb612 |
| registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:044c8eb67015101ffce22194238d84043f9df5fa827b58338b03d2d18f1e07b5 |
| registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:2ff1702a8b616ddb4131cf7f946ed52f3118312dbd2a2495e526252a373ea7d4 |
| registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:bc351dc60528e0d529fa7328b2dbf8158402b0bdf772ce79f5034e9dd6aeddc3 |
s390x
| registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:4082e7b9ff98f5bd197cfb3e81df42e49f9350faedfb9568bac0b4a9b2bebcfd |
| registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:e23c211f9fab586197b0887cae0aa64c493f16da83163a3a8fd92b5a5e0eaeda |
| registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:293914bff83c8aed3bdfec943ffb135d2720469d9e903d238c8702e3b79ef9a5 |
| registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:a384f21967f4c3d08eaf306a0fbc068e766a2ed259f88dd6b599bca81140a119 |
| registry.redhat.io/openshift-logging/vector-rhel9@sha256:5608f9c61c8313b16af057b5a5e64686d1b76f614b988f06d7872a3fd9dd3956 |
| registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:f1223b4a4ded4fed7f0649345e582c3aa8d8be22c49130ac5461a51c45f36499 |
| registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:c66e18e6fbf5f7cb2476b5a05dfdef3b743d70bc25b3732a4e6515b67947821e |
| registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:914e76bca6486d4cb4d5ff95eae65aa51c156dcbe400eaa0714737d59d37fa03 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.