Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:1866 - Security Advisory
Issued:
2025-02-26
Updated:
2025-02-26

RHSA-2025:1866 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: RHODF-4.14-RHEL-9 security update

Type/Severity

Security Advisory: Important

Topic

An updated images are now available for RHODF-4.14-RHEL-9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift DataFoundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API.

Security Fix(es):

  • go-retryablehttp: url might write sensitive information to log file (CVE-2024-6104)
  • PostCSS: Improper input validation in PostCSS (CVE-2023-44270)
  • golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (CVE-2024-45337)
  • golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Data Foundation 4 for RHEL 9 x86_64
  • Red Hat OpenShift Data Foundation for IBM Power, little endian 4 for RHEL 9 ppc64le
  • Red Hat OpenShift Data Foundation for IBM Z and LinuxONE 4 for RHEL 9 s390x
  • Red Hat OpenShift Data Foundation for RHEL 9 ARM 4 aarch64

Fixes

  • BZ - 2294000 - CVE-2024-6104 go-retryablehttp: url might write sensitive information to log file
  • BZ - 2326998 - CVE-2023-44270 PostCSS: Improper input validation in PostCSS
  • BZ - 2333122 - CVE-2024-45338 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html

CVEs

  • CVE-2019-12900
  • CVE-2020-11023
  • CVE-2022-49043
  • CVE-2023-44270
  • CVE-2024-6104
  • CVE-2024-12797
  • CVE-2024-45338

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

odf4/mcg-cli-rhel9@sha256:0a9094a597ac62a99593d88fd69926096c95263e9daf230d0335d54ad6de81bc
odf4/mcg-core-rhel9@sha256:9435512b7d2a884db40f3db43d920bd97ca30ed13e40d9edde5c795575af284a
odf4/mcg-rhel9-operator@sha256:433c0d3c5a67ff18dcfc678a3822f8b75f2d7e3893288f0789ff42fd7859372f
odf4/ocs-client-rhel9-operator@sha256:7e7d1c77d57f127557ae64adaf86e54e9aa40a7007f6f68669b4034f480e2a10
odf4/ocs-rhel9-operator@sha256:d30f7c21f94cde19e22bf66f28bea9e7dbb39bd633a2fdab997ea98461092c9a
odf4/odf-csi-addons-rhel9-operator@sha256:218a0645d31f93b04485f57a23769b224fb0d03dbe348b37a7e4738fb00c50fe
odf4/odf-csi-addons-sidecar-rhel9@sha256:8f9faddd049d3838e3f36dc9ef0880b3fca4d5eec690fcd2e14c30e1ea0ad01b
odf4/odf-multicluster-rhel9-operator@sha256:47c2726092a6f583ad6c264421c8afe71dc5b031f91f015da06ffa96a123df68
odf4/odf-must-gather-rhel9@sha256:8a68c882ed9fc2b74a9e04bf70de5fcae720df36f8ce5517f9aa1e0324a7e666
odf4/odf-rhel9-operator@sha256:49902142cec52e7a36e1dade3fcf09de4046859f8341866d30573022404b9e20
odf4/odr-rhel9-operator@sha256:bb57b187efe30f5f568b2856e6bb5d07caff6668c3a00d1619142ebc10c4216c

ppc64le

odf4/cephcsi-rhel9@sha256:e724d086d9e0e28c42ce997bb477d2db86e36d1c448050e8b4611b98ad89eab5
odf4/mcg-cli-rhel9@sha256:5e401b1a41c2fc866705bfc5492e734423f9bf5844f00ef510131f401a2abf5d
odf4/mcg-core-rhel9@sha256:5876a75d34b860e73accd588abdf09cf2e59ff38f47ce9b7f2f002ceb2a7bd5a
odf4/mcg-operator-bundle@sha256:3f1d1e16618f28acb70c4c9ed5e6675f2b5e41079ad4d77850b8b3b2e8433b31
odf4/mcg-rhel9-operator@sha256:48965c2c3bc1ab26e2d541f9dbf0096d21f8611aa98ceaee12de70d54d004aa1
odf4/ocs-client-console-rhel9@sha256:07d6dce26001a288dc23f19a04af4407312edc36506ce961abdb7cf44f5017ad
odf4/ocs-client-operator-bundle@sha256:ad6314b15e7eb64b4e3a296dcc618077ec8bed1ecd068e3693781882a2d3f5b4
odf4/ocs-client-rhel9-operator@sha256:9e7a9d7573c7ad5da4e4c587f1331ea50a36cca88d53ddf601b9b49e82c4c197
odf4/ocs-metrics-exporter-rhel9@sha256:f2123e511713530ba2d9bbabe7e9cb2ba962a1c6e3a9c60fbb1c591d9bbcb8cb
odf4/ocs-operator-bundle@sha256:b2a40ed10d663ab7d9fa4f97157b231e14d259feb80d0c40b8acc613fec3b5a9
odf4/ocs-rhel9-operator@sha256:6c764f7ce5a5c475cadefed076a54a0a16a201cc29105c5b43d0a0c26cc82c78
odf4/odf-console-rhel9@sha256:0edbfe8e6c44bdd68c3607dc7f9b4d5fc987d7658762ba7ac1f330c8067b361e
odf4/odf-cosi-sidecar-rhel9@sha256:bab6055f131d58735079521ea094ad9ce3ab3dec91c264a79dc643f3fa31c896
odf4/odf-csi-addons-operator-bundle@sha256:c6be9eb2435d9dd644bb5a1029176659c74328791892803a3c927d9e7c8e6253
odf4/odf-csi-addons-rhel9-operator@sha256:68d7d0e086a9389a4e112c958fc8d80cd898ad9bb45419f892805e181dbb9067
odf4/odf-csi-addons-sidecar-rhel9@sha256:45a680e3d5076ad7c490fd2703f825f3519c80990af79bd922d25b8c12f8c6a8
odf4/odf-multicluster-console-rhel9@sha256:53fd29412365a97cab53ce1bf746be3e057b46b1489699e81f818e468aed2e3f
odf4/odf-multicluster-operator-bundle@sha256:e92ec14b55a289de5285e4ce3a00968f2971ece31e8707eb1a1fd13c593e2b2e
odf4/odf-multicluster-rhel9-operator@sha256:9ad9d59c0a7554c7f4e36243a0d7a3a32f8c626d785dedbefc2e4e744e9fab12
odf4/odf-must-gather-rhel9@sha256:c402e9c54585dacdadb021463f4e3b4e8ffc27261e19d8213fa81c28feeba86b
odf4/odf-operator-bundle@sha256:5e193e7d80edc0e1190385e64479b5d3ced732f776687088732f2812835faa21
odf4/odf-rhel9-operator@sha256:6b8f43af0d31b5c884e5550839575e71dd76fa2f8a977b692d35c62e9ae8f7d3
odf4/odr-cluster-operator-bundle@sha256:4daecbbbbef6c27da3c4a63aed768ee86e5a4958eff751521b65f5332512acfc
odf4/odr-hub-operator-bundle@sha256:33c8c519b3c9f22a08655373297f5d9d722f84d7ef5e456f038e0a53d9170b16
odf4/odr-rhel9-operator@sha256:4fe5bcf40f1ec800dfa6af1b119a1acb5c042e3b67a9801a12309bb41d4c571e
odf4/rook-ceph-rhel9-operator@sha256:bd047c468e19a9df538ef512b57246a11c834a422b053cf9e7cc04267b5704a9

s390x

odf4/cephcsi-rhel9@sha256:01119cd6e5cdc5aed68fd23ad8192925a561b38f049c7d153858407f9263f151
odf4/mcg-cli-rhel9@sha256:e314a3e4193deb5187a9fd5c56c70a2b63d55c5ae22f304c01c5ad27114b38d6
odf4/mcg-core-rhel9@sha256:cdc4c487c5c228748e2dfdb280181bcff122cc00f2c7be0eabe917c66c557f36
odf4/mcg-operator-bundle@sha256:15dff59b4e787dc97ce8d773680376d5902db0d86326182dd19f5ec5865ddc85
odf4/mcg-rhel9-operator@sha256:99a092112bb85b1afcdb5c5ed2cf4a0ace07d33efef18a78b83f9ed1ae7d5e89
odf4/ocs-client-console-rhel9@sha256:cf04ad2b6891da8f4e246da41041543817666b18e372e7ed4cc655b3b30bf96b
odf4/ocs-client-operator-bundle@sha256:7467d33d1e7831d991468b2ca6b74e7e0b39c24c9aac3f2ff8e7986e4f58ddc2
odf4/ocs-client-rhel9-operator@sha256:2f2116f744ac245e24da9264fd1bd7ac645b85329717ad9e6681deceb45ae09e
odf4/ocs-metrics-exporter-rhel9@sha256:35ec07d822ed1394405049d40bf1acb1c572568590d7ee21e0091e53ebe3043d
odf4/ocs-operator-bundle@sha256:b115bfb31941cccddfa4167901919e1b98cc24c47e8e4b4a063e3298ae674c9d
odf4/ocs-rhel9-operator@sha256:9dec5c1f21a8439bfa1928cde05399bb429d62984dc218ac6426215314383a1c
odf4/odf-console-rhel9@sha256:b4a62adde5184a0879412bf19361c059dd1e3a9f93b9e5df3e3105de064a0c56
odf4/odf-cosi-sidecar-rhel9@sha256:a9b9817c057303b7129b134cd9f180f7c8e5389bf3ad0ff76d9ef3af5bef4815
odf4/odf-csi-addons-operator-bundle@sha256:aa48fa3c772308937ed1e2403b4a0e48996795ee82922f7f5cd4bf18e056801d
odf4/odf-csi-addons-rhel9-operator@sha256:ceb390a001fe4f11f1363833e1e4b4fe4112a980e03449726af7725842916628
odf4/odf-csi-addons-sidecar-rhel9@sha256:ef5ee8cf24e576a3236d0de809aaff3392f262c14b5d11be1afc4c7eb8457075
odf4/odf-multicluster-console-rhel9@sha256:4178f6964f6b59c5926159d69bb4c50ea795b3ef63c5458afc7ce003b158e935
odf4/odf-multicluster-operator-bundle@sha256:73dca4c7fd04cae31691f9b577feeb34402116538ab832564eb6534f2b9b6428
odf4/odf-multicluster-rhel9-operator@sha256:f6f26c682e2d107cf7196208088273bbd6e8ef7a1c8fa8bc2e2aeb0c50d9b27d
odf4/odf-must-gather-rhel9@sha256:6eaffe344c0c6e1e5c48f8d296153dc045929e740357f6cee2f8446fe1414029
odf4/odf-operator-bundle@sha256:4a59791b0760ef7d7c6e921a7435e8d45a617c326f0bb2d922d5d50105af9d80
odf4/odf-rhel9-operator@sha256:8cea94cd68f0da5d4c45de4e63d992cfbb652d47448acb08a908f7b45cc58b56
odf4/odr-cluster-operator-bundle@sha256:cea8e7922cb6fd8b779eeade5d9e146de09e06d2b3ecf268d8e8e3259c68c780
odf4/odr-hub-operator-bundle@sha256:820fdb3b818b4dfb5b7cd21286f551ac7a590c662b64d1f8e9b9ecc7bd1a3535
odf4/odr-rhel9-operator@sha256:858ad3706bdc4986f17b1108c3fbe2c0528648d8777e35a32e439d1001019c67
odf4/rook-ceph-rhel9-operator@sha256:4e796478bb8dcdac2c0c66a300869ff24c3b9e146342d911f59aa7475ed679f6

x86_64

odf4/cephcsi-rhel9@sha256:875f3639444793baf0783faff34acf22d8266f85bee8fe0fe71debaf0c04b577
odf4/mcg-cli-rhel9@sha256:084c38bd692c8233d1d44484e621b01a840049e497bdcd2af7621d8ce805071b
odf4/mcg-core-rhel9@sha256:87426cde2a152397e9ee28c52ed503d098924154f257acbe04787ba2a797416f
odf4/mcg-operator-bundle@sha256:ef15da624e99f6f8e34cefeb7f16cffc13285d597d5f760815c57798e01bddd9
odf4/mcg-rhel9-operator@sha256:67c617a9b48c9fc683e945357d3a9bc515c6c96f782deaf573e756b42ecddf8d
odf4/ocs-client-console-rhel9@sha256:7d49faa18106a5e4c3c2be4fd4471e1778737dcef54d9c22cbcca33216eddc24
odf4/ocs-client-operator-bundle@sha256:38de7a19d4636f17551b2fe76840a61accb2ec4ac39b7b6f815670e25fd085f3
odf4/ocs-client-rhel9-operator@sha256:78bbd4ab235e453540615037c1074563d588808a9169d9e3f44665d3231d49c2
odf4/ocs-metrics-exporter-rhel9@sha256:b602ecd4a663f56597d7219e8a88d362425b5ebfcb205fa05c9d3045094c7010
odf4/ocs-operator-bundle@sha256:1ca40f8ac50059887ec1e644ba86d73e85ee3c6d8d3f96faa016dab44f3948fe
odf4/ocs-rhel9-operator@sha256:85c8c4c7065638c39cb5eebd3a5b81cbe6e6f400466878b650c16ca8040cb499
odf4/odf-console-rhel9@sha256:7b6954eb8a40c21bbf96c5a3d7beb9ddf72b51bc3b4158d3d9e6cd4d78fb5340
odf4/odf-cosi-sidecar-rhel9@sha256:43fcd99bd76b47b4a3fce37f22eb21c3863fb551f5e4c4fd5e1e6fe119a84a58
odf4/odf-csi-addons-operator-bundle@sha256:3f5f77af30b78b05fdc1506df7d12573a64de5054393520ea77308955625ee7e
odf4/odf-csi-addons-rhel9-operator@sha256:acc06903597646b70ceeaf1fe3bcd717422f2754af7eb6da8adb8bd77f615617
odf4/odf-csi-addons-sidecar-rhel9@sha256:efd2166e54d301556e5ca2e861787f7e64454fa9630fb26382bd23f12f3b16f7
odf4/odf-multicluster-console-rhel9@sha256:21d3ab818610bb644d8c0b3eaa6879993b3e10efb183167c770194fe2bb18917
odf4/odf-multicluster-operator-bundle@sha256:b47f867bb6adc802996fe912d2bb42cf1993ed4c80142c2249c26c4815d339d6
odf4/odf-multicluster-rhel9-operator@sha256:a2c898656e50a23f3aa0b9749136dd7e24c5843be6eb6f970c04fbb5e3d7925b
odf4/odf-must-gather-rhel9@sha256:76455baade072661b5e22173f949b6e469b2006dbaf532101cc369c641d2b2ac
odf4/odf-operator-bundle@sha256:1949d6e635c671ce9539efa6178f55d1ebbb88630609574df927331cc1cf3b7d
odf4/odf-rhel9-operator@sha256:35ce153a5f0907509cadbb270b83e8513d23b17e2a1d4af866a286857e4a0e6a
odf4/odr-cluster-operator-bundle@sha256:525a970131defaf6d6c4e5600b7e9cafab21abfe3424cbcff76096b42594e75d
odf4/odr-hub-operator-bundle@sha256:25d5a07860c8da2cd193e1547a1afccee42ff0650956dd486d0362dc53d6d4f5
odf4/odr-rhel9-operator@sha256:cf0630a115e1bbad794496dfc44ab53b9c7e817eae81c4802c374b0e9bf7a1e1
odf4/rook-ceph-rhel9-operator@sha256:75dde5a45e6274c6f7c152986fd3d73e79edd4dfd75e8aab6c946336bd82fb9a

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility