Red Hat Security Advisory: OpenShift Container Platform 4.17.15 security and extras update
🔗 CVE IDs covered (12)
📋 Description
CVE-2024-21538 — cross-spawn: regular expression denial of service
CVE-2024-43796 — express: Improper Input Handling in Express Redirects
CVE-2024-43799 — send: Code Execution Vulnerability in Send Library
CVE-2024-43800 — serve-static: Improper Sanitization in serve-static
CVE-2024-45296 — path-to-regexp: Backtracking regular expressions cause ReDoS
CVE-2024-45338 — golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html
CVE-2024-45590 — body-parser: Denial of Service Vulnerability in body-parser
CVE-2024-48910 — dompurify: DOMPurify vulnerable to tampering by prototype pollution
CVE-2024-52798 — path-to-regexp: path-to-regexp Unpatched path-to-regexp ReDoS in 0.1.x
CVE-2024-55565 — nanoid: nanoid mishandles non-integer values
CVE-2024-56201 — jinja2: Jinja has a sandbox breakout through malicious filenames
CVE-2024-56326 — jinja2: Jinja has a sandbox breakout through indirect reference to format method
🎯 Affected products188
- Red Hat OpenShift Container Platform 4.17
- openshift4/ingress-node-firewall-rhel9-operator@sha256:1e88032295ab6a57e87102870144234fd4d00af4d64692998d94aec1da0fa7e2_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ingress-node-firewall-rhel9-operator@sha256:1eca125f06e0accfef2233f5baf68c683a05e10e7edafd3894b10a5c9832ed7b_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ingress-node-firewall-rhel9-operator@sha256:ab569dfb349e365f7ad9dc2c90ab40bcc45daaaa829286f9c9020c3efc1e72a0_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ingress-node-firewall-rhel9-operator@sha256:de584540e7ce6842dde472058d62bc0460a00a18e4d523629cf3a2ce2d3e7d90_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ingress-node-firewall-rhel9@sha256:33303a9781c6d420d2a0927c6fc718d85909375547022c542bfb2cac54f908cc_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ingress-node-firewall-rhel9@sha256:4a54958572d4ca2a7b657e81dec2d85fa1f282bc4e557d1a3d222720d2fa40d8_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ingress-node-firewall-rhel9@sha256:f3d37e0fbcdf83bc5292ca7a7b5c495aad0d8611211bb72499492573a797ce54_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ingress-node-firewall-rhel9@sha256:f4e365279bc71a9e4b34354f4f92db16df722e04d90b19bc2abe3f85d896899f_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/kube-compare-artifacts-rhel9@sha256:62e5a756d35969806d9e2a2bb1f8be00925496a92188d883c259f1baaa168d83_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/kube-compare-artifacts-rhel9@sha256:99c9a64e58f220e5494d162c6a7c5ff10fdef49e96ed5f48c0e7b5937c2cc12e_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/kube-compare-artifacts-rhel9@sha256:9cebbb5a9d84389762dcc411ae5a05899ecf3e7b66eba09a176cc9bd8de8bbdc_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/kube-compare-artifacts-rhel9@sha256:fe8a449229062204e3ac9650b357e3d9414d7be467173b067bcef8e7b0d0c6e4_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:1ad9d78189f80c226312ed8fb18a117b71cb128cfa965c35dfc14f62b8c51c16_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:1f7a9fbeab09bf9d95f43a786da9e4cb550f0aecaed7c1f4b948a1386b166fdd_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:bf1197d47e48a2355497deba62bdfaab5c43dd284db5bcaec69262329667ba6b_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:e7392111911a2d8117276327aa5488284b596ba88444159b0a8d97c7c4f129e8_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/metallb-rhel9-operator@sha256:4997f775c57c4ff923a0c49545142916eca0c14053031b546c499345a74b3fe4_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/metallb-rhel9-operator@sha256:8095681987eca0a5f01d897bf19a5f3a48cb51e71b186e188f8c7430e635fd68_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/metallb-rhel9-operator@sha256:b8503c978f235e2451cafd50cc07ccf3cda5d4842e6fcb57b4e1d713f61e6f4f_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/metallb-rhel9-operator@sha256:e1a6e1b8ec81b432b87eceec71184c13349d24ed00b075449d0cfe24f94dbdd3_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/nmstate-console-plugin-rhel9@sha256:05995ad1c1db13694adeacfa2ec37199001f9eb0b37618f3c392c4bce85fc106_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/nmstate-console-plugin-rhel9@sha256:255aa4123181bc6045d1c9bca83add43b8e64b4b7c614f6d2f111fec8e098a0f_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/nmstate-console-plugin-rhel9@sha256:e3ab6aa63cdcf2e7d086d9ca6a25117ccb287e2165580a4bcd682d35e7343438_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/nmstate-console-plugin-rhel9@sha256:e4a88c8181e4c02121ad638a4e0220b176bda1981f72e26574696cae40f15aef_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-ansible-rhel9-operator@sha256:1cf906f1a9b35a3829990f8a802e4e617de7b32a091d22ff3b291b02a6de1629_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-ansible-rhel9-operator@sha256:5aedff51d5c18d6e6b0834efabec523490a6fe17571ed181b9094194d2532bff_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-ansible-rhel9-operator@sha256:5eb3e62ff2a8f4bbc51513081415a964aaaed2b9770d6111f69bc31df891d00c_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-ansible-rhel9-operator@sha256:9ed511e02d2f30114e2f3772c99f3f9e7037a3748d8d2da39f059091ea6b02f4_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/ose-aws-efs-csi-driver-container-rhel9@sha256:0707f47c27331e77140e17cbd5ba0dc5324096d165ebb5078df7b4bb6bb4ef64_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- +158 more not shown
✅ Remediation
For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.17/release_notes/ocp-4-17-release-notes.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Avoid using two parameters within a single path segment when the separator is not, for example, /:a-:b. Alternatively, you can define the regex used for both parameters and ensure they do not overlap to allow backtracking. Workaround: To mitigate this vulnerabilty restrict user-controlled template filenames, ensuring they follow a predefined templates.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2025:0875
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2310908
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2311152
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2311153
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2311154
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2311171
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2322949
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2324550
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2330689
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2331063
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2333122
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2333854
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2333856
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_0875.json