First published: Wed Mar 05 2025(Updated: )
Logging for Red Hat OpenShift - 5.9.12<br>logging-fluentd-container: Possible Log Injection in Rack::CommonLogger [openshift-logging-5.9](CVE-2025-25184)
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Logging Subsystem for Red Hat OpenShift | ||
Red Hat Logging Subsystem for Red Hat OpenShift | ||
Red Hat Logging Subsystem for Red Hat OpenShift | ||
Red Hat OpenShift Logging |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2025:1985 is classified as moderate.
To fix RHSA-2025:1985, you should update your Red Hat OpenShift logging subsystem to the latest version.
RHSA-2025:1985 affects the Logging Subsystem for various architectures including IBM Z, LinuxONE, IBM Power, and ARM 64.
RHSA-2025:1985 describes a possible log injection vulnerability in Rack::CommonLogger.
If you cannot update immediately for RHSA-2025:1985, you should implement mitigations to limit exposure and monitor logs closely.