Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:8479 - Security Advisory
Issued:
2025-06-04
Updated:
2025-06-04

RHSA-2025:8479 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: RHODF-4.16-RHEL-9 security update

Type/Severity

Security Advisory: Important

Topic

Updated images are now available for RHODF-4.16-RHEL-9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift DataFoundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API.

Security Fix(es):

  • express: cause malformed URLs to be evaluated (CVE-2024-29041)
  • nodejs-async: Regular expression denial of service while parsing function in autoinject (CVE-2024-39249)
  • body-parser: Denial of Service Vulnerability in body-parser (CVE-2024-45590)
  • npm-serialize-javascript: Cross-site Scripting (XSS) in serialize-javascript (CVE-2024-11831)
  • http-proxy-middleware: Denial of Service (CVE-2024-21536)
  • golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338)
  • golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing (CVE-2025-30204)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Data Foundation 4 for RHEL 9 x86_64
  • Red Hat OpenShift Data Foundation for IBM Power, little endian 4 for RHEL 9 ppc64le
  • Red Hat OpenShift Data Foundation for IBM Z and LinuxONE 4 for RHEL 9 s390x
  • Red Hat OpenShift Data Foundation for RHEL 9 ARM 4 aarch64

Fixes

  • BZ - 2290901 - CVE-2024-29041 express: cause malformed URLs to be evaluated
  • BZ - 2295035 - CVE-2024-39249 nodejs-async: Regular expression denial of service while parsing function in autoinject
  • BZ - 2311171 - CVE-2024-45590 body-parser: Denial of Service Vulnerability in body-parser
  • BZ - 2312579 - CVE-2024-11831 npm-serialize-javascript: Cross-site Scripting (XSS) in serialize-javascript
  • BZ - 2319884 - CVE-2024-21536 http-proxy-middleware: Denial of Service
  • BZ - 2333122 - CVE-2024-45338 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html
  • BZ - 2354195 - CVE-2025-30204 golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing
  • DFBUGS-1702 - [Backport to 4.16.z] rook-ceph-osd-prepare-ocs-deviceset pods produce duplicate metrics
  • DFBUGS-714 - [2316908] [ODF 4.16 backport]cluster-cleanup-job pod not cleaning /var/lib/rook
  • DFBUGS-2603 - [Critical] Upgrade ceph version to RHCEPH-7.1z4 at ODF-4.16.10

CVEs

  • CVE-2023-23934
  • CVE-2023-25577
  • CVE-2023-46446
  • CVE-2023-48795
  • CVE-2024-8176
  • CVE-2024-11831
  • CVE-2024-21536
  • CVE-2024-24790
  • CVE-2024-29041
  • CVE-2024-34069
  • CVE-2024-39249
  • CVE-2024-42353
  • CVE-2024-45338
  • CVE-2024-45590
  • CVE-2024-47191
  • CVE-2024-48916
  • CVE-2025-0395
  • CVE-2025-27516
  • CVE-2025-30204

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

odf4/mcg-core-rhel9@sha256:88b3cbebf2d0d9959c9485e3bd92e8d20f5d51781b3e5e3604695d24e3df5ba5
odf4/mcg-rhel9-operator@sha256:7139e479209a6a4ab60bd398220a48ca78a6cdeabc09619371fb80bba2beeba3
odf4/ocs-client-rhel9-operator@sha256:63b44fd5c9a991e008ce2af1745d5eb280252874a50cb87254bb599a28e0db78
odf4/ocs-rhel9-operator@sha256:407dc5605eda149ce8077c729d25e611a4da61390c26e0cca7e79a04f4066799
odf4/odf-cli-rhel9@sha256:b41d13ab01eda036441e7c4b937685ae824803fbe9df0cc4ff921ba62f65aa27
odf4/odf-csi-addons-rhel9-operator@sha256:5c93247842fcfa844ae884bd7723aad467037f541c23792a5938c9d8647cffaa
odf4/odf-csi-addons-sidecar-rhel9@sha256:89ce5b5d2a834bb0656638a7ef18e81f72faf7ceb247d953d333aaeb38126456
odf4/odf-multicluster-rhel9-operator@sha256:6b04ecd021150e18bd7eff95782776234b9eb34793d729df9e0ba8e063a76d05
odf4/odf-must-gather-rhel9@sha256:992cf0fd0be01edaabc747055a5ab54e87cf300f15c7f56f915e15a9c8611681
odf4/odf-rhel9-operator@sha256:8c5cb83ec1a1a0b88e7d90d0af33492afb3e4101974ae534ecd56384442e591c
odf4/odr-rhel9-operator@sha256:23ff8963c2045ee1cf124a6f891316bbebfb07503abdf7fbfede068336485bd9

ppc64le

odf4/cephcsi-rhel9@sha256:9e722e6ef66d768ad25c4029a6f4796b3035a8e0bcab1eea3b0b9e3e0ac80a2c
odf4/mcg-core-rhel9@sha256:13f94d78bbea30a1e87a3b71f167272268f88ec6cadd46baf0d41b6c78001207
odf4/mcg-operator-bundle@sha256:2271d7696060f1308cddc9f0b39484a3c896ceae0934a22a4967e4e550c6411a
odf4/mcg-rhel9-operator@sha256:092bd757a65a2932ec92a31e745c21125e4fbda1058e75e8f53e35bd757182a7
odf4/ocs-client-console-rhel9@sha256:56e8b7e50e7f4e018cbfd59710ecd4283e8faa1c18d83f8acd40ec0821f540c6
odf4/ocs-client-operator-bundle@sha256:1f39071fe02977accce7c0ef31b71f6e337dbb6b7f918ca7f73c34dd2c1197de
odf4/ocs-client-rhel9-operator@sha256:ef0121ba44fc3e770156cb122d13f3ca2165ef6578995814f6053752eacf0ab4
odf4/ocs-metrics-exporter-rhel9@sha256:cb63f2994222ad8736a6f4fd757fb683162ab3c16f59d9a17253b01dc940650e
odf4/ocs-operator-bundle@sha256:0190226401fdd645ab2faf41da6b3d3484d73446116cfce28b4c4ccd7f9535a2
odf4/ocs-rhel9-operator@sha256:c3b0b210bf0e79c22b61973d7a21a6df93dd64b0b86744ee3e62f89bb777f12c
odf4/odf-cli-rhel9@sha256:d078327210b3bd99b49eb8eb19af66c5807dffbc2e2e4aae00acebd58ecb520a
odf4/odf-console-rhel9@sha256:d720823a6088c721948429c16f8ff14963c06c5d502b78c114d01064d3e929fd
odf4/odf-cosi-sidecar-rhel9@sha256:e38f277a083409ee3349b0ea72198de5c34a3933e143529f9fec3fff519b997e
odf4/odf-csi-addons-operator-bundle@sha256:65678188e42c0f2b45911747c59f76729d65ba87f6be3550262326f0a851716c
odf4/odf-csi-addons-rhel9-operator@sha256:0bdfb394fb0183f5b6f64227ff7e679f7e0d6d477cc1552902c10afd1ba9f99d
odf4/odf-csi-addons-sidecar-rhel9@sha256:21f9abd9e6ee1919acbac1bdeb8da0e19ef487d8194d1a7b01bd5dcbf59c53b1
odf4/odf-multicluster-console-rhel9@sha256:3ff95e3204a6498cdc70214ae90f0c2f78e8db89142eda8ba9203d5f8fb82636
odf4/odf-multicluster-operator-bundle@sha256:a83130b15970a595987e30eee691ce3d61d87f7d09b7aa947ed4194f5dbfe2cf
odf4/odf-multicluster-rhel9-operator@sha256:759ecf8e346f20e42144034420696dc4242085f9f62d2f27eda18aef5f5ca0be
odf4/odf-must-gather-rhel9@sha256:e2e61ebc92d92d602f27c7de085f35e20a8aa7370c6e279147a1504e6f50a82d
odf4/odf-operator-bundle@sha256:7617bef0ff752c391968eaf8a44071c523004a398190900b94a34ad18eda790f
odf4/odf-prometheus-operator-bundle@sha256:4e6e05dd719c1574b62d1f7eb979b8fb97029247ce6018684f404647ca4efc10
odf4/odf-rhel9-operator@sha256:324765db75f7c4db2d6a37788d7f73caf7479e2c920ffdbc8ae356e0d777fd45
odf4/odr-cluster-operator-bundle@sha256:2729388f45fc61f655978ed14f37e18c6ed16f85309e78466c4f1341b5f36a6e
odf4/odr-hub-operator-bundle@sha256:5dcbea69a771dc585b91b522c2651b074ac46069714b423d9a5f5c7373c90f70
odf4/odr-recipe-operator-bundle@sha256:ac2facf3fa56a11a05d12f007a4cf3040118d5561425d5cd0cae6a793d9a7fa2
odf4/odr-rhel9-operator@sha256:cb3b973a8615dde69bceec9eb8b7c9fc02b0e29573cfe582aa5e3c77f3bd146a
odf4/rook-ceph-operator-bundle@sha256:5cb3e9a9068002a4afc179906295ac242e03e4fb180fad83296cc6086d6e44f7
odf4/rook-ceph-rhel9-operator@sha256:65631c9e67c6c7fc8d8514609a7768e8bb75592e2442358e3958ac6fb0ffa9be

s390x

odf4/cephcsi-rhel9@sha256:8df6be202d7352da9fe45510e26a1fa17ee29b43851bb34f92a36d550145d1c8
odf4/mcg-core-rhel9@sha256:8e3e4d47fce84f50a8bc3a6564e588ffce84082c32026ab16e300cb4c9179f34
odf4/mcg-operator-bundle@sha256:ee6ebb4c88c990561f36695a0446d2a5bbed74f37a8bb641ec05dce0c7ae4907
odf4/mcg-rhel9-operator@sha256:7d0d36581b0f43e6c4611165cc7ab6ecc401971d50aa0d7ffd43ce7314c1aec4
odf4/ocs-client-console-rhel9@sha256:faace26bf5dcab6de85a350b65dc13529b6b8ea1e4efe54a4f1cd0cb94f72a12
odf4/ocs-client-operator-bundle@sha256:02275650f8f2a4432f74ce61d2ad77aef628a49e15a5ba968862583875356c5b
odf4/ocs-client-rhel9-operator@sha256:3062c425ca8380884d424b4d96ca08414a9369337f3056c890b197dcca313be4
odf4/ocs-metrics-exporter-rhel9@sha256:9f944006b8fd489a75ea48598266605be7931feba94346472c030a3842a56cdb
odf4/ocs-operator-bundle@sha256:83e63a6cfbcb9b24fd0d7ac47d436801d9488ca2ada18e08fd6534f9d5f5bf14
odf4/ocs-rhel9-operator@sha256:14c09bf9ff056dba8f9f7cbfe8a01a573b3e1ea6435121afad703f85f2127fe3
odf4/odf-cli-rhel9@sha256:874b75ca4d3c05e0146be35fd6a52585bb287c8fdd2450abe391e7a7d2983d17
odf4/odf-console-rhel9@sha256:da249713d3306e6fa468fff12dca94b087bf4e6cda935a8d588f913a72660ae1
odf4/odf-cosi-sidecar-rhel9@sha256:22b963c99e8f4c304854bf5deb4d93a22f284c290c0bad71989c1b9661faa545
odf4/odf-csi-addons-operator-bundle@sha256:e72b47011ecd4293c5140280a6023744b847ec811e67aa66c1c55817a9e29c53
odf4/odf-csi-addons-rhel9-operator@sha256:d3698dae91ba7ac556dcd6bcb6e876b9e2e145bb3b7357f616a36eb79c36e13e
odf4/odf-csi-addons-sidecar-rhel9@sha256:8ba9c7f82c772c0b463e28974e18b5c0a8bc628cb14321ad55c683718ae1f144
odf4/odf-multicluster-console-rhel9@sha256:083ff820bf60832efddb8cddf21083a3f331040c23fd9220c1ef261b31ecded8
odf4/odf-multicluster-operator-bundle@sha256:c212acdc3bdb6563063373911fcca169998cdce2cfc40460fc175f4403e90d99
odf4/odf-multicluster-rhel9-operator@sha256:dffb2b522f5641f2b23d58f454ebcecf229ce7a745dc4f55235c9701584acdef
odf4/odf-must-gather-rhel9@sha256:9b25351ffef71bd1f930b94a74e5949e315fd5a2d96b8cdd4d0334f8405046cc
odf4/odf-operator-bundle@sha256:6166bdaa8cf7f8ce29556e3ecdebe4b2408f47d9d86d638e63a1ffd1b5033246
odf4/odf-prometheus-operator-bundle@sha256:75536acc8a28f6af097f3d601ffd95ba3f72413ecaaa8c87cc79c0dd3b91ac0b
odf4/odf-rhel9-operator@sha256:d4214d21e418e1df1c286456778b52ebedda0d1fded37b7fd11a3242380621c5
odf4/odr-cluster-operator-bundle@sha256:a022710a33d5ff1fc41620f9f42f66840d44d8815524f72a9f84d4c401198ce7
odf4/odr-hub-operator-bundle@sha256:3b30801ecae02b61c991745cdebb78c23001030dc8488a49150d88925aa00cde
odf4/odr-recipe-operator-bundle@sha256:2e5344edbc939b55a5799548a2350431f4dc3924677f29493ba4c12009129cc2
odf4/odr-rhel9-operator@sha256:a30b6a0d444ede68c51c2c54e6fad440c68d05bd4a36deecf79f550baf42c18f
odf4/rook-ceph-operator-bundle@sha256:c28f02f01ac29ebe613735aacf82aa48d00c04ea72588f10521884ca43ef9b41
odf4/rook-ceph-rhel9-operator@sha256:b4ea673a120d714e6254c3a209a460ee6e5f3cb39126f22772506bec075fb347

x86_64

odf4/cephcsi-rhel9@sha256:b569f1f1cc542522fad6a9664ffe83135e0fac221da2db858a1e1b3dafac2a78
odf4/mcg-core-rhel9@sha256:266dcc4332512803feb0c2841bd447d5730512d5cd533814a55c7a73fdbbe92f
odf4/mcg-operator-bundle@sha256:0995b3e355f37e1e1ddb7a81afea0a2e1d4b1dcddb8fda460694af1f54b2b852
odf4/mcg-rhel9-operator@sha256:d95d17587043a5980a4a9e2c40474238b17270b48cd28d9286abf37e8dba5229
odf4/ocs-client-console-rhel9@sha256:eddd4bf5d536fad6764c7daf8b36709630566a916e3c9a9c38cb195037e13f36
odf4/ocs-client-operator-bundle@sha256:8ca8073d40aa0d9257094baf33dfa16e56600556259d91306d6d6d7727bcdebc
odf4/ocs-client-rhel9-operator@sha256:0a19077800fec1f56d21b7db0d71da69f0c2e736be6428c854563288780f76ca
odf4/ocs-metrics-exporter-rhel9@sha256:9ab03e07b64cdd003fce3842d5a3bef77c8fa0b0b7b331d6630549ee14d2be22
odf4/ocs-operator-bundle@sha256:9d6259d776788968a8c73580666287ef3aca96f2f233d1113ed508d93342cdba
odf4/ocs-rhel9-operator@sha256:e651f24a541ec7e68d58918c02ffe1f840b042088fb6335947d60713d2634ade
odf4/odf-cli-rhel9@sha256:2c678413a9f31b6a94ea6f89d48e425acb0de6bdb682dd9b5302279675f20af5
odf4/odf-console-rhel9@sha256:72c00c654b5454542fc46516459c42cec8a0df53e3e692391eae178314f38b4f
odf4/odf-cosi-sidecar-rhel9@sha256:f27062101d6044e1a99866ffa801b60c4042f37fab5711180fe6fbdc111e1b32
odf4/odf-csi-addons-operator-bundle@sha256:7a7aebbafb68c841f26cdf8e01be77669957d19673a5e590aa3eec2905327444
odf4/odf-csi-addons-rhel9-operator@sha256:8316c12d61aacbd9e0f6c47b86fda7d13147c70cbf1879ea9a329d3fcd9908cb
odf4/odf-csi-addons-sidecar-rhel9@sha256:c12a1d3140f14ff68169284d6d971ae146453409ae78831f167abd219b7a8237
odf4/odf-multicluster-console-rhel9@sha256:7d804c6a8db583f9a9b7da10a31b0354afc59a8af45dfeaa420482f8370895e2
odf4/odf-multicluster-operator-bundle@sha256:09aa4ad2452ba4039e715c7fd46173b9516004709039a17f4a425e2975d7c4d7
odf4/odf-multicluster-rhel9-operator@sha256:777eb594d74aa36416be4ff29a91bb3376c65ae6faaf699acaa94c80b4715a4f
odf4/odf-must-gather-rhel9@sha256:a415eaad3cec7de971d55aaa029104e94ee0517bbf7fa2b3441b262f7df3b43a
odf4/odf-operator-bundle@sha256:13df48aa60a17df71ac9c94c7d8d34a9c538636f102ab6d0bb07afc01110678b
odf4/odf-prometheus-operator-bundle@sha256:1df3363b4e4ab2da1294c190bd2f251d3598e85b44e118c9436166c49c7a5d1e
odf4/odf-rhel9-operator@sha256:e40a6ba38a84c6b01732959186a03d458b21717b464773779578ddcacbea89e5
odf4/odr-cluster-operator-bundle@sha256:eba1c48a3bc7623886c4cc6f2a92929cca098b547904e90c715caed421d34600
odf4/odr-hub-operator-bundle@sha256:f6344d640c1c58cd3361927ba1e2b6e59263687b45955a681f413778162b602e
odf4/odr-recipe-operator-bundle@sha256:5a581b6418cb691fb4b04443bd5c53757aa74a18dc38784aebb68c0d4ac94199
odf4/odr-rhel9-operator@sha256:cccbd64631690db519312ca7be0b9ed51f9ede127858f5f1afe780ff4bbbc163
odf4/rook-ceph-operator-bundle@sha256:917339caccb55aae090f31407d7353ec5fc35a80187bfe8f658a443b7d7ebe35
odf4/rook-ceph-rhel9-operator@sha256:9fe8900d98e184012706518bbb76786726c71bad2b370618094887b90359a4a1

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility