Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:8551 - Security Advisory
Issued:
2025-06-04
Updated:
2025-06-04

RHSA-2025:8551 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: Red Hat OpenShift Data Foundation 4.14.18 Bug Fix Update

Type/Severity

Security Advisory: Important

Topic

Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.14.18 on Red Hat Enterprise Linux 9 from Red Hat Container Registry.

Description

Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API.

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Data Foundation 4 for RHEL 9 x86_64
  • Red Hat OpenShift Data Foundation for IBM Power, little endian 4 for RHEL 9 ppc64le
  • Red Hat OpenShift Data Foundation for IBM Z and LinuxONE 4 for RHEL 9 s390x
  • Red Hat OpenShift Data Foundation for RHEL 9 ARM 4 aarch64

Fixes

  • BZ - 2270863 - CVE-2024-29180 webpack-dev-middleware: lack of URL validation may lead to file leak
  • BZ - 2290901 - CVE-2024-29041 express: cause malformed URLs to be evaluated
  • BZ - 2292777 - CVE-2024-37890 nodejs-ws: denial of service when handling a request with many HTTP headers
  • BZ - 2295035 - CVE-2024-39249 nodejs-async: Regular expression denial of service while parsing function in autoinject
  • BZ - 2311171 - CVE-2024-45590 body-parser: Denial of Service Vulnerability in body-parser
  • BZ - 2312579 - CVE-2024-11831 npm-serialize-javascript: Cross-site Scripting (XSS) in serialize-javascript
  • BZ - 2319884 - CVE-2024-21536 http-proxy-middleware: Denial of Service
  • BZ - 2322949 - CVE-2024-48910 dompurify: DOMPurify vulnerable to tampering by prototype pollution
  • BZ - 2324550 - CVE-2024-21538 cross-spawn: regular expression denial of service
  • BZ - 2333122 - CVE-2024-45338 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html
  • DFBUGS-2605 - [Critical] Upgrade ceph version to RHCEPH-7.1z4 at ODF-4.14.18

CVEs

  • CVE-2023-23934
  • CVE-2023-25577
  • CVE-2023-46446
  • CVE-2023-48795
  • CVE-2024-8176
  • CVE-2024-11831
  • CVE-2024-21536
  • CVE-2024-21538
  • CVE-2024-24790
  • CVE-2024-29041
  • CVE-2024-29180
  • CVE-2024-34069
  • CVE-2024-37890
  • CVE-2024-39249
  • CVE-2024-42353
  • CVE-2024-45338
  • CVE-2024-45590
  • CVE-2024-47191
  • CVE-2024-48910
  • CVE-2024-48916
  • CVE-2025-0395
  • CVE-2025-27516

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

odf4/mcg-cli-rhel9@sha256:eb314a5553470a5a881e277b1962f7219ee0968d4319e55cb7427258a73e3a25
odf4/mcg-core-rhel9@sha256:657f10ecba6e3e484483cc2bdfc7a7cda10f1fab85360c40bb9ef4f1929c4cf2
odf4/mcg-rhel9-operator@sha256:5e932572c6cc187fe1791abe29b71d5fdeb2c0e7a81ed90b46cb3d358aa25e71
odf4/ocs-client-rhel9-operator@sha256:e8860ec492739e0eee28bdefb5934d4274ef9bc49d4d74fb9015153a39958af8
odf4/ocs-rhel9-operator@sha256:96f3aedecbf2afce4050cf63930c016c70e190590ebf6786ac8ddf407dc17a1f
odf4/odf-csi-addons-rhel9-operator@sha256:91d930b98e7e77857d76c5f0de8f33d7129eb1899cd33e34a81e5fb132fe1939
odf4/odf-csi-addons-sidecar-rhel9@sha256:4ac05e6f5da14f77aa642c86d1bc9487c7d4229b3845e4df78dbe70ca7e80836
odf4/odf-multicluster-rhel9-operator@sha256:cc1549214c6df5e4a1a1d578bde3cfb40e529c8bdf721a0d66315b60220f02bb
odf4/odf-must-gather-rhel9@sha256:707709aa3d410109ff94dace09c191683d1c329da6c929f5046e9e36e9f196ee
odf4/odf-rhel9-operator@sha256:b4e8e09091410747c9e10954e37e24e23bf1df970ef8ac4b41e3f01296b92466
odf4/odr-rhel9-operator@sha256:3565d7ed884cb5a102edef6109da8d37d248ba58a1f273949ff94d525c2fb29c

ppc64le

odf4/cephcsi-rhel9@sha256:b9f6fb8c6e5a919ff7b1aead2e220db45e010d285aa3134a060865f98dc8ff4d
odf4/mcg-cli-rhel9@sha256:590d6f1c2d28e9750fb2bffec2dd60d943e6f3de5e3bf801917055c9053d55cb
odf4/mcg-core-rhel9@sha256:7600a8dcc458fdf3b029667c361b3babf0a42a8a8194bb3c90216abb0d37e617
odf4/mcg-operator-bundle@sha256:1eef1245af12bd0049fa88de90549ce23e6098f08cd8273fcbe1552ce5841f98
odf4/mcg-rhel9-operator@sha256:1b220688bcbade808c2fc05d9160547b21fc34672ff653cb16360d485c721669
odf4/ocs-client-console-rhel9@sha256:86a2494cfd358f367ea250d8199d9baa2d6da7a0c6366ed03a55b0648da52c24
odf4/ocs-client-operator-bundle@sha256:5c84ed51c74952ca24757662d3c4856b90cf0a4d856b3807f0c0b57752072b97
odf4/ocs-client-rhel9-operator@sha256:a5e0d9864da87cbb2e787b51f44c9c1c4b5d73bb24aa6660e0bab25c68fa3e78
odf4/ocs-metrics-exporter-rhel9@sha256:d4358fa87319d6aad05d24410df40d297dc1d7d9f871ad53968d9b989b4a0c04
odf4/ocs-operator-bundle@sha256:1ac7a4b8174013392bcd7d1b3d2750a29ffa0e12690f75214397e32fef5d0053
odf4/ocs-rhel9-operator@sha256:16c65fa945a5c4acfa93c74ae48008480fa719c58a3045883bb71374008a9860
odf4/odf-console-rhel9@sha256:b38f1e2be1d00434a69704568ee1c0325dbcd2fd5af187815cc7a926d2954274
odf4/odf-cosi-sidecar-rhel9@sha256:89163387bcc55041336e7e789ce1c2c22bcbba051253df27380a7067a5d34f71
odf4/odf-csi-addons-operator-bundle@sha256:9cc58ece0e07286bd6b645ee0958383fab4760058ab441e40262115a37f7fc08
odf4/odf-csi-addons-rhel9-operator@sha256:8d0d772c6abdf6850cc914b33dbcacf04e56482aed44727d8fcd62484a769ba7
odf4/odf-csi-addons-sidecar-rhel9@sha256:22af185eeb91be6ce4f946819717f3dc6f26a0cb01ad735fedf5ce5c31cee9ab
odf4/odf-multicluster-console-rhel9@sha256:3fa07513b80ec362b896594733f39869f20de9075a9ed659575dac80fb2e50c6
odf4/odf-multicluster-operator-bundle@sha256:aa9d5d9a90379dfa3d208d19bea5fe0ca1358594b12949002cf91b313d5103ba
odf4/odf-multicluster-rhel9-operator@sha256:0fd956965990fdb47a000886906d164dab8770f8810b6f535b30363cbebb193a
odf4/odf-must-gather-rhel9@sha256:adb5cb009e39713cebf5dc677647a1588ca6913437aba15a1f17611055a3b556
odf4/odf-operator-bundle@sha256:c78c6dd624406ef896035e3ea107b32367a9f02d27184086370546ed2b21d03f
odf4/odf-rhel9-operator@sha256:855addbd5d6838d751b679d13c8c1a722b144bf67b1f04465488beeeb4bb7f12
odf4/odr-cluster-operator-bundle@sha256:4864bdc13255f399060b23acb338c0cab89bb12b1e9c25b425bed2708c703916
odf4/odr-hub-operator-bundle@sha256:23d29a80150ec4b20d9a042fe09e6803d420aeedbd7bb97ca6b71898714fa50d
odf4/odr-rhel9-operator@sha256:6c556ff4a2554502498dfbdb6cf34045b812c974b1449862ff0389fc3590012e
odf4/rook-ceph-rhel9-operator@sha256:450d1d15edfe450040967702dfcad42d332f590953dcdfb3f7aca95f3a331156

s390x

odf4/cephcsi-rhel9@sha256:e741ce258ceffff394b453da219439e788a7c60277569d2145667b0f1a27cefc
odf4/mcg-cli-rhel9@sha256:7d462a0cb3bdaf33e7f1d68d2cc2c3b65937e97687a36a6c5f0c21002cba339b
odf4/mcg-core-rhel9@sha256:58883135500207c3f149882421ab3d7c14ee8c934c107d563d1ac51d9dad2188
odf4/mcg-operator-bundle@sha256:b70c0ff1f0c5c44f62d77927a3cb4fb22aa7924ba802b09d2f8ef66258522462
odf4/mcg-rhel9-operator@sha256:dd9c5f35896ff7a7aa622510f969343e3d8c582659753dc6f8aa40bf21ce258f
odf4/ocs-client-console-rhel9@sha256:3739dbc4cfe67226e97b803279f65a017031d60b24a944d031232ce579a2501b
odf4/ocs-client-operator-bundle@sha256:fb23e5e9463322406db0671616bad500c99d201386e38b6298165d169b32e8f1
odf4/ocs-client-rhel9-operator@sha256:30b766091deb8fca244ba8133226fcb71f06caea4601266875cb201b2c05df9d
odf4/ocs-metrics-exporter-rhel9@sha256:823e1ad6153e94cb6aa52b92652c23082007af7127a9510aa025e5ebf67c3959
odf4/ocs-operator-bundle@sha256:74c32e2703174adcbc40d6a022c8760b7109d427efe4a1bba9894ccf1b55a77f
odf4/ocs-rhel9-operator@sha256:2388a24c8af1fc05838cdf9e9cd11e5e7c480a496384247120fe2e62b6ec8c72
odf4/odf-console-rhel9@sha256:355041c3ff87e109ae1a6cd8cf7ef6e3057015072baefb4ecc97c4c23459a5fb
odf4/odf-cosi-sidecar-rhel9@sha256:178b3909c6e97052a4931abafac49680dc443139dd8e06f84048e37383369c33
odf4/odf-csi-addons-operator-bundle@sha256:f774072bc4483ac626a4aa34fb4753a4c8dde1392e90b2cf5088942558187651
odf4/odf-csi-addons-rhel9-operator@sha256:d9d84e12ac2cbc4d6b3bade470963db183576a0f03e53fb524cec61affcaadc0
odf4/odf-csi-addons-sidecar-rhel9@sha256:b7e8dac029bb2e4d43a3318da70c1ab9e78c834a425c0b4b580f194c51c5fcfe
odf4/odf-multicluster-console-rhel9@sha256:c76a2aa281b7f23694cad709563ae38f6a2612b03b6dea758800925d1fb0d1e7
odf4/odf-multicluster-operator-bundle@sha256:4a3c1211a5b08832eea9014edb8f15908a4c64da4929a5535e21e5f5f0ce7440
odf4/odf-multicluster-rhel9-operator@sha256:5c32c4e197c2cd9642ecd4dfebcbf0793920722adb1669175471074595d6e85c
odf4/odf-must-gather-rhel9@sha256:b4747d5081a27c2b4159142c7673d367f2205b6da373386142edfc9b6e1f7e4e
odf4/odf-operator-bundle@sha256:1595d223f68167f107979b76b5a3adba064b75cacec6618fbedaaedf723a0b6c
odf4/odf-rhel9-operator@sha256:616dacc42b9e39aada7d97a80fbeef591b48f2dc13b9a614e1762f0fcfc67ae1
odf4/odr-cluster-operator-bundle@sha256:784af1811346b0d1a41774a05bb8fddd829c8fe11058ce0dd27e2e916a0fd50f
odf4/odr-hub-operator-bundle@sha256:003c68a08b13aa517cacec54ba71d677bc2077b98c56e44527d8709de9542b81
odf4/odr-rhel9-operator@sha256:6267de184448e87a5e4386c40e85b35dbe8b9d0e41809f30d45d75e425cf34d9
odf4/rook-ceph-rhel9-operator@sha256:563003275c2eb1f9769f8e64d8ec9c280d2ae68ea60a4b72e078c3d3934e6107

x86_64

odf4/cephcsi-rhel9@sha256:bcb328a210baf1ccff7c7373d8cb80f951c8902e6f1b25f543e248923ff11bf1
odf4/mcg-cli-rhel9@sha256:dae4433fdd1054a34badc70ce5db933c936f9e270cbc93a03a408beac0731ee6
odf4/mcg-core-rhel9@sha256:88643caf11bdef38053b7972a376035591e4ecfe03ed7a52b618211b1e1c3e6f
odf4/mcg-operator-bundle@sha256:c3143fd1da13f7470f07df869630c4de1cd3c390676e096b2cc61df1ce0b3c20
odf4/mcg-rhel9-operator@sha256:b93a4133ab036f4a44471e9c8ac0274e9651177d72ae3fdf1d73bbacb31b2e63
odf4/ocs-client-console-rhel9@sha256:0db1703649e40cdb563f269ccfb0e80724f13034b21e9c5482ea22a82af61b85
odf4/ocs-client-operator-bundle@sha256:a32c47c452fce1a32a15880b9e5c2c561e656a26c143cc46a54368fcaa614863
odf4/ocs-client-rhel9-operator@sha256:b9d281eb35128e5f1c96ba1383259dff9b2e60dbb27c092f27de4f2e12a8f08c
odf4/ocs-metrics-exporter-rhel9@sha256:541fd697cc7cad79abd38c1ea593745d8b89153cc82137136cbfa840257d8dca
odf4/ocs-operator-bundle@sha256:6989d9c619455ec241c7629170e8fa2994b94fbde5f31b03d83ddf26572a3ac0
odf4/ocs-rhel9-operator@sha256:5fb501bb9da6e224cf496eca1e0f5b3de4acb12a770725eb81ddbf703c703b3e
odf4/odf-console-rhel9@sha256:52b0a09f6cb2d8ac7ad1412fede0ae0a8f849f3a51009ab5cec9630cb01cc504
odf4/odf-cosi-sidecar-rhel9@sha256:adbeae924b38597ac5a25d183b95d1466e93d22850b41a7b5e55ffdd6c925875
odf4/odf-csi-addons-operator-bundle@sha256:048b52f424309a244c829a29199126a3700c34999f567adc205264192df18e40
odf4/odf-csi-addons-rhel9-operator@sha256:58d332ed50ac84a78ae3f874af7bc3078505e1f39504cff98f5c96ca577dba62
odf4/odf-csi-addons-sidecar-rhel9@sha256:53ea6080dbc702be75df81c9b27f53f8d5200f9de059d0e2ddf7d4f7c8943bf8
odf4/odf-multicluster-console-rhel9@sha256:18fb47b295feed7c13b7b8e0ab0779a0f1ad0ba920a98de3114e9c963b37da16
odf4/odf-multicluster-operator-bundle@sha256:b20e2a1c687499d1b356f983c896feeffb120ee7913386cf9846f805f5adf078
odf4/odf-multicluster-rhel9-operator@sha256:54d8a857fb70a44333721f7ee19f7465e44f40e9041a1feaa5ad21a7c9e64fc1
odf4/odf-must-gather-rhel9@sha256:bf5e586204aa10fd361322123bf0924ea6f112d7418ea6d50f3fa732c38f18cf
odf4/odf-operator-bundle@sha256:aef5fa1799fdd49f75e6cf00348e811c14792929fe4c454b5180392b506bb92a
odf4/odf-rhel9-operator@sha256:35c52a3cba34e249a4da7cbefbbe2de72d9c6fd28ef6ba27ea278d1664bea4ad
odf4/odr-cluster-operator-bundle@sha256:0cb12e9d9368dd9ba989a7feb5f5a068c5e86a46c3e007be824e8b245c084e55
odf4/odr-hub-operator-bundle@sha256:f762ea7b249c2b9e1b77ca861bfa2e66fb5a2e86bf1c46adcab2c0d3f0962b17
odf4/odr-rhel9-operator@sha256:16b242ff1b14953c3e0d8e6c6aee1907b58e2ea8847c55e698c0dcea113786c4
odf4/rook-ceph-rhel9-operator@sha256:70141f91e796afbf0dad29869b9bbe31af4b86175836d00dcb55f79e9de54302

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility