RHSA-2025:1118HighCVSS 7.3
Red Hat Security Advisory: OpenShift Container Platform 4.13.55 packages and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-56201 — jinja2: Jinja has a sandbox breakout through malicious filenames CVE-2024-56326 — jinja2: Jinja has a sandbox breakout through indirect reference to format method
🎯 Affected products9
- Ironic content for Red Hat OpenShift Container Platform 4.13
- Red Hat OpenShift Container Platform 4.13
- openshift-kuryr-0:4.13.0-202501071752.p0.g36754b7.assembly.stream.el8.src as a component of Red Hat OpenShift Container Platform 4.13
- openshift-kuryr-cni-0:4.13.0-202501071752.p0.g36754b7.assembly.stream.el8.noarch as a component of Red Hat OpenShift Container Platform 4.13
- openshift-kuryr-common-0:4.13.0-202501071752.p0.g36754b7.assembly.stream.el8.noarch as a component of Red Hat OpenShift Container Platform 4.13
- openshift-kuryr-controller-0:4.13.0-202501071752.p0.g36754b7.assembly.stream.el8.noarch as a component of Red Hat OpenShift Container Platform 4.13
- python-jinja2-0:3.0.1-6.el9.2.src as a component of Ironic content for Red Hat OpenShift Container Platform 4.13
- python3-jinja2-0:3.0.1-6.el9.2.noarch as a component of Ironic content for Red Hat OpenShift Container Platform 4.13
- python3-kuryr-kubernetes-0:4.13.0-202501071752.p0.g36754b7.assembly.stream.el8.noarch as a component of Red Hat OpenShift Container Platform 4.13
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: To mitigate this vulnerabilty restrict user-controlled template filenames, ensuring they follow a predefined templates.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2025:1118
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2333854
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2333856
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1118.json