RHSA-2025:0082: Important: Red Hat OpenShift Data Foundation 4.16.5 Bug Fix Update

Published Jan 8, 2025
·
Updated

Important: Red Hat OpenShift Data Foundation 4.16.5 Bug Fix Update

Other sources

Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API.<br>Security Fix(es) from Bugzilla:<br><li> dompurify: DOMPurify vulnerable to tampering by prototype pollution (CVE-2024-48910)</li> <li> tough-cookie: prototype pollution in cookie memstore (CVE-2023-26136)</li> <li> css-tools: Improper Input Validation causes Denial of Service via Regular Expression (CVE-2023-26364)</li> <li> net/<a href="http:" target="blank">http:</a> Denial of service due to improper 100-continue handling in net/http (CVE-2024-24791)</li> <li> path-to-regexp: Backtracking regular expressions cause ReDoS (CVE-2024-45296)</li> <li> express: Improper Input Handling in Express Redirects (CVE-2024-43796)</li> <li> send: Code Execution Vulnerability in Send Library (CVE-2024-43799)</li> <li> serve-static: Improper Sanitization in serve-static (CVE-2024-43800)</li> <li> nanoid: nanoid mishandles non-integer values (CVE-2024-55565)</li> <li> cross-spawn: regular expression denial of service (CVE-2024-21538)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Red Hat

Affected Software

4 affected components
Red Hat Red Hat OpenShift Data Foundation for IBM Z and LinuxONE
Red Hat Red Hat OpenShift Data Foundation for RHEL 9 ARM
Red Hat Red Hat OpenShift Data Foundation for IBM Power, little endian
Red Hat Red Hat OpenShift Data Foundation

Remediation

Event History

Jan 8, 2025
Advisory Published
via Red Hat·11:27 AM
Feb 5, 2025
Advisory Published
via Red Hat·01:57 PM
Data Sourced
via Red Hat·01:57 PM
RemedyDescriptionAffected Software

Frequently Asked Questions

1

What is the severity of RHSA-2025:0082?

The severity of RHSA-2025:0082 is classified as Important.

2

How do I fix RHSA-2025:0082?

To fix RHSA-2025:0082, you should apply the latest bug fix update provided by Red Hat for OpenShift Data Foundation.

3

Which products are affected by RHSA-2025:0082?

RHSA-2025:0082 affects Red Hat OpenShift Data Foundation for multiple platforms including IBM Z, LinuxONE, RHEL 9 ARM, and IBM Power little endian.

4

What type of vulnerability is addressed in RHSA-2025:0082?

RHSA-2025:0082 addresses a bug fix update in Red Hat OpenShift Data Foundation.

5

Is there any guidance provided for RHSA-2025:0082?

Yes, the Red Hat advisory for RHSA-2025:0082 includes guidance on applying the updates to mitigate the identified bugs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203