RHSA-2025:0082: Important: Red Hat OpenShift Data Foundation 4.16.5 Bug Fix Update
Important: Red Hat OpenShift Data Foundation 4.16.5 Bug Fix Update
Other sources
Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API.<br>Security Fix(es) from Bugzilla:<br><li> dompurify: DOMPurify vulnerable to tampering by prototype pollution (CVE-2024-48910)</li> <li> tough-cookie: prototype pollution in cookie memstore (CVE-2023-26136)</li> <li> css-tools: Improper Input Validation causes Denial of Service via Regular Expression (CVE-2023-26364)</li> <li> net/<a href="http:" target="blank">http:</a> Denial of service due to improper 100-continue handling in net/http (CVE-2024-24791)</li> <li> path-to-regexp: Backtracking regular expressions cause ReDoS (CVE-2024-45296)</li> <li> express: Improper Input Handling in Express Redirects (CVE-2024-43796)</li> <li> send: Code Execution Vulnerability in Send Library (CVE-2024-43799)</li> <li> serve-static: Improper Sanitization in serve-static (CVE-2024-43800)</li> <li> nanoid: nanoid mishandles non-integer values (CVE-2024-55565)</li> <li> cross-spawn: regular expression denial of service (CVE-2024-21538)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:0082?
The severity of RHSA-2025:0082 is classified as Important.
How do I fix RHSA-2025:0082?
To fix RHSA-2025:0082, you should apply the latest bug fix update provided by Red Hat for OpenShift Data Foundation.
Which products are affected by RHSA-2025:0082?
RHSA-2025:0082 affects Red Hat OpenShift Data Foundation for multiple platforms including IBM Z, LinuxONE, RHEL 9 ARM, and IBM Power little endian.
What type of vulnerability is addressed in RHSA-2025:0082?
RHSA-2025:0082 addresses a bug fix update in Red Hat OpenShift Data Foundation.
Is there any guidance provided for RHSA-2025:0082?
Yes, the Red Hat advisory for RHSA-2025:0082 includes guidance on applying the updates to mitigate the identified bugs.