Skip to navigation Skip to main content

Utilities

  • Abonnements
  • Téléchargements
  • Console Red Hat
  • Assistance
Red Hat Customer Portal
  • Abonnements
  • Téléchargements
  • Console Red Hat
  • Assistance
  • Produits

    Produits Phares

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    Tous les produits

    Téléchargements et Conteneurs

    • Téléchargements
    • Packages
    • Containers

    Ressources principales

    • Documentation produits
    • Cycles de vie des produits
    • Conformité produits
    • Errata
  • Base de Connaisances

    Red Hat Knowledge Center

    • Solutions Knowledgebase
    • Articles Knowledgebase
    • Labs Portail Client
    • Errata

    Docs Produits phares

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    Toutes les Docs Produits

    Formation et Certification

    • À Propos
    • Index Cours
    • Index Certification
    • Skill Assessment
  • Sécurité

    Centre de Sécurité des Produits Red Hat

    • Mises à jour de sécurité
    • Alertes de Sécurité
    • Base de données CVE Red Hat
    • Errata

    References

    • Bulletins de sécurité
    • Indices de gravité
    • Données de sécurité

    Top Ressources

    • Labs de sécurité
    • Règles de rétroportage
    • Blog sécurité
  • Support

    Support Red Hat

    • Dossiers d'assistance
    • Résolution de panne
    • Obtenir de l'assistance
    • Contacter Red Hat Support

    Support Communauté Red Hat

    • Communauté Portail Client
    • Discussions Communauté
    • Red Hat Accelerator Program

    Top Ressources

    • Cycles de vie des produits
    • Labs Portail Client
    • Configurations prises en charge par Red Hat Jboss
    • Red Hat Lightspeed
Ou dépanner un problème.

Sélectionnez la langue

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure et gestion

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Informatique Cloud

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Stockage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat Openshift Container Storage

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Intégration et automatisation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
Tous les produits
Errata des produits Red Hat RHSA-2025:1985 - Security Advisory
Publié :
2025-03-05
Mis à jour :
2025-03-05

RHSA-2025:1985 - Security Advisory

  • Aperçu général
  • Images mises à jour

Synopsis

Moderate: Logging for Red Hat OpenShift - 5.9.12

Type / Sévérité

Security Advisory: Moderate

Sujet

Logging for Red Hat OpenShift - 5.9.12

Description

Logging for Red Hat OpenShift - 5.9.12
logging-fluentd-container: Possible Log Injection in Rack::CommonLogger [openshift-logging-5.9](CVE-2025-25184)

Solution

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:

https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html

For Red Hat OpenShift Logging 5.9, see the following instructions to apply this update:

https://docs.openshift.com/container-platform/4.14/logging/cluster-logging-upgrading.html

Produits concernés

  • Logging Subsystem for Red Hat OpenShift for ARM 64 5 for RHEL 9 aarch64
  • Logging Subsystem for Red Hat OpenShift 5 for RHEL 9 x86_64
  • Logging Subsystem for Red Hat OpenShift for IBM Power, little endian 5 for RHEL 9 ppc64le
  • Logging Subsystem for Red Hat OpenShift for IBM Z and LinuxONE 5 for RHEL 9 s390x

Correctifs

(none)

CVE

  • CVE-2020-11023
  • CVE-2022-49043
  • CVE-2024-12797
  • CVE-2025-25184

Références

  • https://access.redhat.com/security/updates/classification/#moderate

aarch64

openshift-logging/cluster-logging-rhel9-operator@sha256:6b4d17867f342c80119174af037319568da13562dfd3c0319cace2ec097b56bf
openshift-logging/eventrouter-rhel9@sha256:f94ea569cfb249ae3ba5ed77d8a8de2624709c3262fb61821bcf4466bd1b9679
openshift-logging/fluentd-rhel9@sha256:53502bf985083b07d159add436f4ba24b70c9246dff454e766cd320b626ba295
openshift-logging/log-file-metric-exporter-rhel9@sha256:f4e999a27aafe23d0cf947586ee97ccb1213587f9df463684a1a26e42fd2bae1
openshift-logging/logging-loki-rhel9@sha256:ea8e27415923a9e2437d1627451cacd42e60c3f103c0526cb9e80304dada6307
openshift-logging/logging-view-plugin-rhel9@sha256:522daafc39886ccccfb5021677da932d915f6befc82a0e61bb3895224bf19f26
openshift-logging/loki-rhel9-operator@sha256:d2e3d0876a74b06a96b446444cb21ecb5ada1079a32ea4a9f31ac17717ff6329
openshift-logging/lokistack-gateway-rhel9@sha256:67f60fa2dfc91485b6ec95bce9b50d21571e4943d0da0e267de7521e98ca7726
openshift-logging/opa-openshift-rhel9@sha256:eb993be4498a6e223d9af749da2a9cb806e24ef94b1616bfbf21b266e7e39013
openshift-logging/vector-rhel9@sha256:403ab62d8d09c22018fdeab60cfa66b0a3b95c9ad66c746a530583c764abe25c

ppc64le

openshift-logging/cluster-logging-rhel9-operator@sha256:b7e786cb7930c5a40faf0da45d2c508996103e975463d7062f22e97b04cd3f66
openshift-logging/eventrouter-rhel9@sha256:f86cc7235333b698c32f8cca0ef5b30432faaef6f741c74e2bd4cb7372b57784
openshift-logging/fluentd-rhel9@sha256:d56a8ce8304ebea3e31471b4cf76e93e859e176de09343b97d4e4dc5948d35fa
openshift-logging/log-file-metric-exporter-rhel9@sha256:90fb7da86b96e612eb2e5792f91c651383f0b924802e5adb38bc8c3438fc9947
openshift-logging/logging-loki-rhel9@sha256:4351b3f86d054b81035342c768efbc2d6add9f287879a52eb26dd167182be52a
openshift-logging/logging-view-plugin-rhel9@sha256:6d152c585a474fdf0e2557765ce3f8f2c3f595a922f962d573d1d8af8244f78b
openshift-logging/loki-rhel9-operator@sha256:00f258e7f36de191e78dcdb84c3234e86e4313f6c42e1a79843e07a2d5df6efa
openshift-logging/lokistack-gateway-rhel9@sha256:b72504f91b84de22d3bf729dd41b9e332c55b8e615d96fb9d820c223ea2b3bdc
openshift-logging/opa-openshift-rhel9@sha256:558d1e28f23406c86e9a81de0386c8760bbce4607a41b54976bae8e316046ac8
openshift-logging/vector-rhel9@sha256:0ace4ecf9c320930bc78ad4913eb809d0d6aad169bab97dce5aabe9e87104974

s390x

openshift-logging/cluster-logging-rhel9-operator@sha256:141e74fe4ad031ac2bdb2ddbe752a9c96a9d295e0c3e8d6a72748aa96014a64f
openshift-logging/eventrouter-rhel9@sha256:8c3b1e75f6a764814725978dd07e22562a7fe516bdc7ff99f604559487a1b972
openshift-logging/fluentd-rhel9@sha256:5591c4896d634481d947eb3a54576e07f0acff792ba863a0c3087f9af5c150e2
openshift-logging/log-file-metric-exporter-rhel9@sha256:98d6bed0aea9e2673b7dd446a77774f6a463dfa0eac7536dfdeee841bfd23c13
openshift-logging/logging-loki-rhel9@sha256:f9b34a964c6ef07f284f02b3015373058bae6487b490d9c06bb22adc97ce596c
openshift-logging/logging-view-plugin-rhel9@sha256:d182b56563a159698aa673989280fbaed3d680d8a4203cf6e1d679a6aef1e76c
openshift-logging/loki-rhel9-operator@sha256:84cad12a9223d84f339fdb2ffe944620d2fff39f4be2fe34fed6ee7fe4a8393f
openshift-logging/lokistack-gateway-rhel9@sha256:0329f021f8da5ad11404eb58cf72f4a56bdf348c841991b623f4228d3346130a
openshift-logging/opa-openshift-rhel9@sha256:972d09709f8497901132b6ef7bb0f90f99d4e037ec6b34924b3fb8c50a43bfd2
openshift-logging/vector-rhel9@sha256:59fef65a96e45a2046184e20fe71053f15b7576ec3ec4250e402adf9923c8b5b

x86_64

openshift-logging/cluster-logging-operator-bundle@sha256:0fd4b24fdc4ae0777f8c520128396a453d38970f47a4c9cf56e7bfcc27c73e19
openshift-logging/cluster-logging-rhel9-operator@sha256:24e8c777298eaad22b4ba4377bb40281b7a75022ad02e2a4671f0da4ab86fdff
openshift-logging/eventrouter-rhel9@sha256:6e2301ab3451f05e5e6b8bcf1fa80e6a86bde93704138b987494c1d46ca1c5e3
openshift-logging/fluentd-rhel9@sha256:2fadd17b19306cc6d89001ff711c5e6cc8be12eafc8dae9b3bade30f790a90bf
openshift-logging/log-file-metric-exporter-rhel9@sha256:d2eb63a201ea1f72281e3fac2b8570283a76f11f85a60531cd038df85411b43f
openshift-logging/logging-loki-rhel9@sha256:2ef2825c9c25faf8ce52280ebeb7b7b2539fe8598e472b86c1f80c7839e69bce
openshift-logging/logging-view-plugin-rhel9@sha256:bc7f66033624f69545b759f73924a59a432771b1c52c6ee601ae9e7a9787d81b
openshift-logging/loki-operator-bundle@sha256:3fa2044534b778f7616417e9c31c35446ffc79c6a68f6fd4ffcaeb8f64e3ea34
openshift-logging/loki-rhel9-operator@sha256:697f7a1604a5e0ce0779702ad6d946b7eca54803422de442a9cf1667479f6603
openshift-logging/lokistack-gateway-rhel9@sha256:973d6e68e17a1ab6acf00a4fb476a1a21ff051745a4d2a2aa48e09199eb61ee6
openshift-logging/opa-openshift-rhel9@sha256:4597bbf7d9e74912e841a7ce04482fec4af766dd3c78aff5590b5b4c603ab75b
openshift-logging/vector-rhel9@sha256:8e022f187c2e05433697da4b1c8d2bfcfb9458a03fa81103e4b7ac2b0db1ae68

Le contact Red Hat Security est secalert@redhat.com. Plus d'infos contact à https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Liens rapides

  • Téléchargements
  • Abonnements
  • Dossiers d'assistance
  • Service client
  • Documentation produit

Aide

  • Nous contacter
  • FAQ du Portail Client
  • Aide relative à la connexion

Informations sur le site

  • Faire confiance à Red Hat
  • Politique de prise en charge des navigateurs
  • Accessibilité
  • Prix & récompenses
  • Colophon

Sites sur le même sujet

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • À propos de Red Hat
  • Jobs
  • Événements
  • Emplacements
  • Contactez Red Hat
  • Blog Red Hat
  • Inclusion at Red Hat
  • Red Hat Cool Shop
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Déclaration de confidentialité
  • Conditions d'utilisation
  • Toutes les politiques et directives
  • Accessibilité numérique