Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:1865 - Security Advisory
Issued:
2025-02-26
Updated:
2025-02-26

RHSA-2025:1865 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: RHODF-4.15-RHEL-9 security update

Type/Severity

Security Advisory: Important

Topic

An updated images are now available for RHODF-4.15-RHEL-9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift DataFoundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API.

Security Fix(es):

  • go-retryablehttp: url might write sensitive information to log file (CVE-2024-6104)
  • node-gettext: Prototype Pollution (CVE-2024-21528)
  • PostCSS: Improper input validation in PostCSS (CVE-2023-44270)
  • golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (CVE-2024-45337)
  • golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Data Foundation 4 for RHEL 9 x86_64
  • Red Hat OpenShift Data Foundation for IBM Power, little endian 4 for RHEL 9 ppc64le
  • Red Hat OpenShift Data Foundation for IBM Z and LinuxONE 4 for RHEL 9 s390x
  • Red Hat OpenShift Data Foundation for RHEL 9 ARM 4 aarch64

Fixes

  • BZ - 2294000 - CVE-2024-6104 go-retryablehttp: url might write sensitive information to log file
  • BZ - 2311014 - CVE-2024-21528 node-gettext: Prototype Pollution
  • BZ - 2326998 - CVE-2023-44270 PostCSS: Improper input validation in PostCSS
  • BZ - 2333122 - CVE-2024-45338 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html

CVEs

  • CVE-2023-44270
  • CVE-2024-6104
  • CVE-2024-21528
  • CVE-2024-45338

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

odf4/mcg-core-rhel9@sha256:852b4d896884f0d4e81f9d8a29335953a01153771ff885adba95ba4fadaba2df
odf4/mcg-rhel9-operator@sha256:7b7c2e424cbebe7b570ff5883cb9d491a5ddeb84013e34fafbcd973645a3937c
odf4/ocs-client-rhel9-operator@sha256:8d568b564063ffe2e0e165fe8abd32764c4ccd37a66e12332c37f83d734a04c0
odf4/ocs-rhel9-operator@sha256:35badc3d587478e800e7a5c4aa8afaebddbddb1663a3fd3b42719f991bf49bc5
odf4/odf-cli-rhel9@sha256:bc4a29711da0917dd078f048fc3b329e28616b97b3f6d16f233b668d8776f042
odf4/odf-csi-addons-rhel9-operator@sha256:e4feecaed528f12dfc40d788241735f890949770c3031300ac60ec70f202a455
odf4/odf-csi-addons-sidecar-rhel9@sha256:71131d040f832fc431e90580e1320d292117699ca831324db144c2faafd874f4
odf4/odf-multicluster-rhel9-operator@sha256:2cf45f505435cb24c2d42c4f46fc54e114cba96f5ddcb3492d287970a11e4eec
odf4/odf-must-gather-rhel9@sha256:6fdc7a2291c2f471e2f1ef985d43c9b73dc11e713cbe5db5c40d969d04c453a7
odf4/odf-rhel9-operator@sha256:3efdbc0a2866553b47998f8b7177ccf35faac6ac0b73e0f60e04ee54e09d94f2
odf4/odr-rhel9-operator@sha256:ec9d7cbd0fca8fbca49f9762d27e75d7481fbf57fd704ddbed526293970848fb

ppc64le

odf4/cephcsi-rhel9@sha256:afd08e6db4609a733b6f8e5833e880bb990195bfa514ddc3aa4575eee0065b55
odf4/mcg-core-rhel9@sha256:e086a3568ee8a53a0f3c1bb1616375bc092a3692de686c1004eaf9bbefa52892
odf4/mcg-operator-bundle@sha256:259d26c041a55ba5c5700ab8c258c4afa8665e7db3c6b6e6d980bdce33cd0e94
odf4/mcg-rhel9-operator@sha256:9fc0d8f34c48b256704f43d4b6b08258a31a37409499c0e5125287118c2add69
odf4/ocs-client-console-rhel9@sha256:0cada446d73b02279aeb4cac590b77d170e11fa69a6fb95c5fbb73a7a986673c
odf4/ocs-client-operator-bundle@sha256:8a5f0ba5ea797e1781ff5bf448bdeda379b8522f5affee0e17f65af47ff462fd
odf4/ocs-client-rhel9-operator@sha256:0a3122df910aaa8f8aa9b6f9cff3151d2f26c4cdde4f089afbc74b327f7cdf49
odf4/ocs-metrics-exporter-rhel9@sha256:7f867f41480a582339915abf6dd28bf72ab61b18259f25ba31c973f376babe15
odf4/ocs-operator-bundle@sha256:4ab804c7b47c6e67b0765d9e8c8c4eae2656fecda26a9b3178a46d5619cc2818
odf4/ocs-rhel9-operator@sha256:bed778e718953f3c77b4a0efd75ae6c6a57e5e400b2318aeed29213e54a0fcad
odf4/odf-cli-rhel9@sha256:1e59d1ead02a248664d23256e1b68467f0bd26a4fbd4de0440d5cac5ccef9f99
odf4/odf-console-rhel9@sha256:3acf0a15b03e691258197b733c908284226f2c13fd37d697b8e6f70a9999fb76
odf4/odf-cosi-sidecar-rhel9@sha256:7a8f0744a6fa5d7eb478c1499b03e66a668f072d144f1646323cdd60e24af99c
odf4/odf-csi-addons-operator-bundle@sha256:41126891aa1ed6358c68d2f47580d6a7fe151d821fb1f97e7156227f933f3471
odf4/odf-csi-addons-rhel9-operator@sha256:3bf4b1a220db153b574c46118c3cdf3f4f4f0cb3ffa9d1da977c7719d9875e22
odf4/odf-csi-addons-sidecar-rhel9@sha256:05867345c93fcd8e42a3f062851e38c8cd0c5476b6b8d19655e9e9a73320f2db
odf4/odf-multicluster-console-rhel9@sha256:a9bb12259074f0b788188db1fa636bc1ab24e98391822eaee023c5be834a5871
odf4/odf-multicluster-operator-bundle@sha256:994968a507774d21a037fcc0b0551b46d97ee56ef471a4a846ea85d4de0ce8a2
odf4/odf-multicluster-rhel9-operator@sha256:a54c636f26a2a0ab99071cb99cfe445d0348b19be0786b0faf040c8694b691df
odf4/odf-must-gather-rhel9@sha256:6b1a4be5cc06782921edd4830d03188477471b059f2517e770bd13c629f7ee97
odf4/odf-operator-bundle@sha256:54ba34edba2c62fe5fc1a918c31798a2fc02ae0f9571093d152df16202be06eb
odf4/odf-rhel9-operator@sha256:23e5b251d2b18eb5f7aec0b9838b2fa32f5aa99ee8bbd7dfb4aababa01005e66
odf4/odr-cluster-operator-bundle@sha256:67382962c4142dd2853c8a3953008768b8beb2c67d28278aa3349fff538d6f0c
odf4/odr-hub-operator-bundle@sha256:87be7bfcc19b6cc49bf95d01ac20d6a18ef3a5d5ffea55d4aa5ba2ee6b76e7b6
odf4/odr-rhel9-operator@sha256:6faa157afd3bc487e2a7dbb0101eefc8706c01320507ec1ff8704bf5773ea549
odf4/rook-ceph-rhel9-operator@sha256:4f1dedbf1e11ca387ab9788b1fee7a103ea2d061ccfb6606c97e2b6ef60e0582

s390x

odf4/cephcsi-rhel9@sha256:d655f9bb7f59a1312674fb56ed799bd413f95a29b58e194efb097f9547ca9320
odf4/mcg-core-rhel9@sha256:2ec44c4660966041f97ab17c90faac384ae286e88ae2cf28c8c43397ce59d4e0
odf4/mcg-operator-bundle@sha256:f81256fda5d97ea6426b7826215092896c8316b1294bb91e68dcef3775916615
odf4/mcg-rhel9-operator@sha256:376f84cf689b35dc6de959679829a279b134676a1d3e7e9f557668b21110eb73
odf4/ocs-client-console-rhel9@sha256:883751a0d9e0caaa601fcb6574fc7da28a992e204908d7259213cf8d20e4f710
odf4/ocs-client-operator-bundle@sha256:b0cf9cb5990f0c8be8670adb2d81f7fc294bb3bfd7ab510f0b41e97f77e5b117
odf4/ocs-client-rhel9-operator@sha256:4fbe08867ed4ff746697a0e984e394fe53c1f91f0f2d8c6c1c154712067ce06b
odf4/ocs-metrics-exporter-rhel9@sha256:d5cc67cf06c7fc1736a107d9d166689e1785d9174c8a8b15c5b820c63e3facae
odf4/ocs-operator-bundle@sha256:51eed73aa49b3d1b8a32176122ee64376333dbfbb0c77a87e19be71f1286b586
odf4/ocs-rhel9-operator@sha256:0dd3bc91da9f9c0c8e0754c92a6471e91aef1515906d9a02bc7cc26aaf0df60b
odf4/odf-cli-rhel9@sha256:1f2e2a5f2ce79b98c836c997152b8de3e9071fa2abacbba03f73b5f4a9301128
odf4/odf-console-rhel9@sha256:86c483ebdace8e4b1997b8f173e79ee21288cdd992d60660ae4469c2721f998b
odf4/odf-cosi-sidecar-rhel9@sha256:2dddfb94279fb6f6c63fc820d25e9b9d35c3ce550a6484c8f5504c0abe2fcd0f
odf4/odf-csi-addons-operator-bundle@sha256:d35f37f0096676079dc522a1ab3eb97ddbcd1547b29101b10abef0d2597eceb6
odf4/odf-csi-addons-rhel9-operator@sha256:a3b2d97b7521e83e40f431e130113339eb897abd14fd1587bd50f54e145b385d
odf4/odf-csi-addons-sidecar-rhel9@sha256:b3fe801834310b67fb71ebdadd2fe394184beada33a3065dac5f8203855f2829
odf4/odf-multicluster-console-rhel9@sha256:2b707873a123f52fdc2102ef4a6f4a08c724b63181d56336ab3799aa45746c74
odf4/odf-multicluster-operator-bundle@sha256:877955567527789f1f1c3c01d1d1634439f200208a6a9e56fd867265440f4952
odf4/odf-multicluster-rhel9-operator@sha256:af26045275c77462fa75cce10c058167b0a75be146fd5a3044f241fdc67974d0
odf4/odf-must-gather-rhel9@sha256:65dc1f1aef0d7ffd8c52373776df4ee7c1296397f4e14d7ed2762946857b2490
odf4/odf-operator-bundle@sha256:fa40f1337de387b3d4900d9bc6686eea54d2578322b92fd86d84d73b88560f4d
odf4/odf-rhel9-operator@sha256:ec441e6c8872890044bd3096c79d7983b3309ea0f99ae71bbc672839525af944
odf4/odr-cluster-operator-bundle@sha256:346f6ee5cb726ef34d89e59bac166afdb980ae154c3af1dac0f1ae3d9572959e
odf4/odr-hub-operator-bundle@sha256:cf42aae06ea6fb2f2cded2ed3c59410951b8093ac2b11dcc901fab6c9516d604
odf4/odr-rhel9-operator@sha256:77a9ed1bc57278694ad64acd1574de16fc72debe728aea5e4a6aadead738633d
odf4/rook-ceph-rhel9-operator@sha256:f7342146421e0c72772954721815e0de40a56e2b470f1618dec87c37bf34358d

x86_64

odf4/cephcsi-rhel9@sha256:c9720ff854b27882dde55e3cec487f6f6f78630ccb427870e848b04689d95417
odf4/mcg-core-rhel9@sha256:42f249a0b7bce82732387362a4e135140bd6338d30d65ba18df97a3e6d752f23
odf4/mcg-operator-bundle@sha256:6020166a85745a92f89bc8070d41e5581c11d7758a0560fe90c7808fec3b4072
odf4/mcg-rhel9-operator@sha256:7ac459cd93f79ca61c4aa6c5f42365bad4e3adda2712cf38f2c9123730171d3e
odf4/ocs-client-console-rhel9@sha256:a7e3ee8a21cac9f7fbf6a99a71b133a71750c2de7bf760d06cb08998472334a3
odf4/ocs-client-operator-bundle@sha256:b5c18f42e9edffea0ae461219ad54911d8f7f6976a640500c03361d923dc238b
odf4/ocs-client-rhel9-operator@sha256:7e35db3cb5f2fb7a4804b541c46b3e53dea3c031a66356ab25519fe26679e281
odf4/ocs-metrics-exporter-rhel9@sha256:c77741fdcd40ffc86046f1b0825f7739de6b333b450d09c9757a19ed4dd22b78
odf4/ocs-operator-bundle@sha256:4ae63ccaaf14f1709243877b2253b72c0e8d2401351d44c010c211130a500515
odf4/ocs-rhel9-operator@sha256:f98616f409bbd033191e204a931fb834d50f6d53327b6cdbc22f6e06b7db7d99
odf4/odf-cli-rhel9@sha256:aa6b6b2819334f60587dc1b03a0aaaf1f69b7309679811f51336c1fda57197fe
odf4/odf-console-rhel9@sha256:307506d6a73ff2b667c5459d73479cdf982521a0c07f0afb127d83a9a3f00a14
odf4/odf-cosi-sidecar-rhel9@sha256:98c004f5c1b1900032e3da7bc8d34aa29156d23bc0a9091515dc3a175699a75a
odf4/odf-csi-addons-operator-bundle@sha256:c412d807f300f273a8c88b5d3d17f1dad389c7598dccdfd3cadfb5635b29085c
odf4/odf-csi-addons-rhel9-operator@sha256:2fd4897c4fecf16bff95a99bfe30ce83006ac5b3479676dd7291117a24c4b431
odf4/odf-csi-addons-sidecar-rhel9@sha256:7b127906ae4f834ed6b2bdd51a11c6cff6d6d055f275c54986247d4ce39b7919
odf4/odf-multicluster-console-rhel9@sha256:d3242c93346aad595ee6dcf80c4069ff14740add22cf58efba815325679d22b9
odf4/odf-multicluster-operator-bundle@sha256:f68b4c01859185916f7dacb11a602d0e3f621f969ff287842cfa6df5262c02cd
odf4/odf-multicluster-rhel9-operator@sha256:427d5e0cd1488026eb28ce002c494b723b5c0fbf9aca650f61217e58714287de
odf4/odf-must-gather-rhel9@sha256:e6f5d0d5dcc72673a4eef0e93b7fbac23ef8f7cf90b373584bee302ef6342b83
odf4/odf-operator-bundle@sha256:2d543d60ed7ccf76813503f0fa49020154702ee9b03aa730f8e05149b0ead94e
odf4/odf-rhel9-operator@sha256:d59a3bd7f639c7590412e333b32922cb00db224c2b6f4659a7886ac3d5a0c3db
odf4/odr-cluster-operator-bundle@sha256:30b1319d9b1eb1b212b467de4998a8e37e2b989fa4f16731c45d1726f56b5b0a
odf4/odr-hub-operator-bundle@sha256:0deea2f8beceec81ef4e21131578198bdebd263fbe7f51f0868e31eced26dd46
odf4/odr-rhel9-operator@sha256:e9f3173d1056e950f92d0b1583c4199436bed0d2a2a2352d889fb2a2cccf766f
odf4/rook-ceph-rhel9-operator@sha256:95fc2a0529fd428294086bfe41bbec3835cfcfa4a8ac6f9a3c3e740a2eacfd1b

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility