Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:7449 - Security Advisory
Issued:
2025-05-14
Updated:
2025-05-14

RHSA-2025:7449 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: Logging for Red Hat OpenShift - 5.9.14

Type/Severity

Security Advisory: Important

Topic

Logging for Red Hat OpenShift - 5.9.14

Description

Logging for Red Hat OpenShift - 5.9.14
logging-loki-container: Non-linear parsing of case-insensitive content in golang.org/x/net/html(CVE-2024-45338)

Solution

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:

https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/ocp-4-14-release-notes

For Red Hat OpenShift Logging 5.9, see the following instructions to apply this update:

https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/logging/cluster-logging-upgrading

Affected Products

  • Logging Subsystem for Red Hat OpenShift for ARM 64 5 for RHEL 9 aarch64
  • Logging Subsystem for Red Hat OpenShift 5 for RHEL 9 x86_64
  • Logging Subsystem for Red Hat OpenShift for IBM Power, little endian 5 for RHEL 9 ppc64le
  • Logging Subsystem for Red Hat OpenShift for IBM Z and LinuxONE 5 for RHEL 9 s390x

Fixes

(none)

CVEs

  • CVE-2019-12900
  • CVE-2020-11023
  • CVE-2024-2236
  • CVE-2024-2511
  • CVE-2024-3596
  • CVE-2024-4603
  • CVE-2024-4741
  • CVE-2024-5535
  • CVE-2024-12797
  • CVE-2024-45338
  • CVE-2025-0395

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

openshift-logging/cluster-logging-rhel9-operator@sha256:a8e669fc967469a7b51566dfa0939dea0461371b0f604bde7c42be14f1810441
openshift-logging/eventrouter-rhel9@sha256:c7616ee2223a7901388850c26e382014e5093d6be41e4ff7011ea24f73b8dbb0
openshift-logging/fluentd-rhel9@sha256:fe949b5966cedd123af58c93a3eef05d8cd5c217c67d0210643f38dc186d26aa
openshift-logging/log-file-metric-exporter-rhel9@sha256:e5946e6bf05e7f5c60c449cb6ec236517a4268fec53068bd221df8e170e360bc
openshift-logging/logging-loki-rhel9@sha256:f59a9472fa97846ebef77ed3529cddb05ce0afb0246b89e233319edb6a1c4007
openshift-logging/logging-view-plugin-rhel9@sha256:7cf55dc5182f3620ec2020584ffa5c91f10c5baa3d40025a28c942e0a128db42
openshift-logging/loki-rhel9-operator@sha256:d4d6abffcaca034a980a0047403787af08c0e48dde7ae662c913e03615067292
openshift-logging/lokistack-gateway-rhel9@sha256:ffd9535dc8196b9dee8baa11cb4f3c0d896a44f6ead1af51274f812319cf4862
openshift-logging/opa-openshift-rhel9@sha256:ad8a4419f6fc58bf587e8a9f606aa80a146119b665ec471ce8049f46f64a67db
openshift-logging/vector-rhel9@sha256:7ff8859b75829191c4738680a4000d809ec5d05db6171e3c74350b31e80b3a06

ppc64le

openshift-logging/cluster-logging-rhel9-operator@sha256:2e1cf02bd81166e4ff5221583d1922688029f64e270c386f883f32f067c7fef7
openshift-logging/eventrouter-rhel9@sha256:e1610c3054a3212e0093e9cdde714721913b324a98902028215159e60b118c2b
openshift-logging/fluentd-rhel9@sha256:75d50e809a6a358ada16d3697d773952be2f09e62edf6ad3cdfe2813d33bf034
openshift-logging/log-file-metric-exporter-rhel9@sha256:6eccfe9faca8911d74cb77fd9016eb919d90c689ec3f202969c9d1ab2651bf66
openshift-logging/logging-loki-rhel9@sha256:fc49b284ae6018cdad12aa9316489e4c18e8c227d26c109574c83165a9151eda
openshift-logging/logging-view-plugin-rhel9@sha256:b2fa18269c8b19e7310941bb7eb82c649f30978e9a88130f3b965d77db3b5518
openshift-logging/loki-rhel9-operator@sha256:956f36837539c484c8b11457577970e603584fa2dd34b5d2f7eb266cf5520026
openshift-logging/lokistack-gateway-rhel9@sha256:0542d5db46e9fc2b866183b872aa0ad63f3b7e145197cd183e154041ec996a9f
openshift-logging/opa-openshift-rhel9@sha256:ac3d6292a61c55a2e243c0229041c0dcfdca3d2bf866cc4815f2b37ca7fa0cec
openshift-logging/vector-rhel9@sha256:c9566d9385fac9ab3d1f43b28fa3ca6ba5fcfb9465e467969eb44dcdef46bfc9

s390x

openshift-logging/cluster-logging-rhel9-operator@sha256:b901351d0005b2c05866ce45bcab7287025d89aac560df379d50d75fbaa53d58
openshift-logging/eventrouter-rhel9@sha256:3d7fc23b4d679b943df2dd0ef2535dc421a25f5e342585bcb31a0c427bb85a2e
openshift-logging/fluentd-rhel9@sha256:210cb7354e14ddff7dfdc2ae05785d321aceea9376b49cfcd47e4f1441b7b46a
openshift-logging/log-file-metric-exporter-rhel9@sha256:017906e5606d858c026f03704a33ac2142ccec5fe6c7d4940f47c322205738af
openshift-logging/logging-loki-rhel9@sha256:b545ff314b2bbc444538d358486d4aa199e40d073a3672aaff4755c825d12ac8
openshift-logging/logging-view-plugin-rhel9@sha256:638702ea0e2794b591672d1c6922c4e820c32929f617146cdc40525447a441a6
openshift-logging/loki-rhel9-operator@sha256:1f58f1a47b01b5077bd6fbd304df3dc119b41f3e63230ed4b8abc503a2a8a58c
openshift-logging/lokistack-gateway-rhel9@sha256:7270a7eaa43baf2d8ac68ae206d6373373667b0eeacf9fe3adef4932c50be903
openshift-logging/opa-openshift-rhel9@sha256:244bb38a303ba974c1a07ce76dfbf2764e9bd4c25d9ef053848df1f5cec112bc
openshift-logging/vector-rhel9@sha256:d4c57997f7d650602d21bf2dc4cb2066d42d0baa4ead2b6b41262d777116f90e

x86_64

openshift-logging/cluster-logging-operator-bundle@sha256:96f911abf6ddb2a502e4e6a7b567df0305b2ad9047441322b33a6df23110a058
openshift-logging/cluster-logging-rhel9-operator@sha256:dc0b1a4630c4f93f1e3634e935f8a99411afe980bab06b2c7ffb94b368aff0d8
openshift-logging/eventrouter-rhel9@sha256:e4b1ef2697b6a6b08ed29480f5f457062c2243c3368500ff29d9ca620c46eeee
openshift-logging/fluentd-rhel9@sha256:a63b79316b30dcd85849bbf41500e5dba28724cfd6fbbd452e89d8ebeadf0d6f
openshift-logging/log-file-metric-exporter-rhel9@sha256:5c4443daf9bfcb5075952178c51ebad74815d90dee59c05af8778ec0750303f4
openshift-logging/logging-loki-rhel9@sha256:0f93870f662a0e2216e23e020cdb16b9903f8b5cf5a6508a2470e6792e860d0d
openshift-logging/logging-view-plugin-rhel9@sha256:9a4d04a94608b97b3113f99b11a8bc3866c1d3bd827a26d105cd99ae2a1be942
openshift-logging/loki-operator-bundle@sha256:c500524adaceea16bee3f12564a9649f9c2b9978878bd927892582219b294ca2
openshift-logging/loki-rhel9-operator@sha256:e605bb71735c632d1e0a3da00803796e24f6baf92da092a78fcdfa45471cf70b
openshift-logging/lokistack-gateway-rhel9@sha256:dec437e5b7f00fd34fd556e4d9fe8d0f14e8a40a5d0a8674377e51f0f101e057
openshift-logging/opa-openshift-rhel9@sha256:bd75a06edc0bf3c8539dae90035d398eb0cc9c5e218d5f739a62338c61b40b5a
openshift-logging/vector-rhel9@sha256:a751601c3127c2745bd4fdf56903b46e5eb69791cc385de52c4b5f4c59cce031

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility