Red Hat Security Advisory: cert-manager Operator for Red Hat OpenShift 1.15.2
🔗 CVE IDs covered (1)
📋 Description
CVE-2025-27144 — go-jose: Go JOSE's Parsing Vulnerable to Denial of Service
🎯 Affected products9
- cert-manager operator for Red Hat OpenShift 1.15
- registry.redhat.io/cert-manager/jetstack-cert-manager-acmesolver-rhel9@sha256:2c54470f4b9e71f11a22259db0026626459cfd75fa1f6ad96af8bd3064bf4e1e_ppc64le as a component of cert-manager operator for Red Hat OpenShift 1.15
- registry.redhat.io/cert-manager/jetstack-cert-manager-acmesolver-rhel9@sha256:6e5e4831bc7c1de6b238a5a72820180265ea5f4d4589cbad0244d211078d75be_arm64 as a component of cert-manager operator for Red Hat OpenShift 1.15
- registry.redhat.io/cert-manager/jetstack-cert-manager-acmesolver-rhel9@sha256:d51c7a02f1f322a651fb258e02e3b4cb99b704f5eb7efce4b691f2ae75a20bc6_s390x as a component of cert-manager operator for Red Hat OpenShift 1.15
- registry.redhat.io/cert-manager/jetstack-cert-manager-acmesolver-rhel9@sha256:e716a4a86a9a8d3065c8de19be72dd2cf63e171a404231052287022f535ef91e_amd64 as a component of cert-manager operator for Red Hat OpenShift 1.15
- registry.redhat.io/cert-manager/jetstack-cert-manager-rhel9@sha256:2ed56c5467b3eed15cf5f940a552d23e8cfee653df64708077d8edbe17f7baaf_arm64 as a component of cert-manager operator for Red Hat OpenShift 1.15
- registry.redhat.io/cert-manager/jetstack-cert-manager-rhel9@sha256:c09abae05168529eca3e247c604760e6912b53ece38c4266978a43405363a97c_amd64 as a component of cert-manager operator for Red Hat OpenShift 1.15
- registry.redhat.io/cert-manager/jetstack-cert-manager-rhel9@sha256:debdf90d1e44dbd41b8df3f1bd45369ff83376d0221d80c2f236b1b1e498a5ef_ppc64le as a component of cert-manager operator for Red Hat OpenShift 1.15
- registry.redhat.io/cert-manager/jetstack-cert-manager-rhel9@sha256:eb81f9a7303eca0ba0d5fccb2682165c4427fccc3ecc7fbdd2056930d39423ca_s390x as a component of cert-manager operator for Red Hat OpenShift 1.15
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. The steps to apply the upgraded images are different depending on the installation plan approval policy you used when installing the cert-manager Operator for Red Hat OpenShift. - If the approval policy is set to `Automatic`, then the Operator will be upgraded automatically when there is a new version of the Operator. No further action is required to upgrade. This is the default setting. - If you changed the approval policy to `Manual`, then you must manually approve the upgrade to the Operator. See https://docs.openshift.com/container-platform/latest/security/cert_manager_operator/index.html for additional information. Workaround: As a workaround, applications can pre-validate that payloads being passed to Go JOSE do not contain an excessive number of `.` characters.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2025:22014
- externalhttps://access.redhat.com/security/cve/CVE-2025-27144
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.openshift.com/container-platform/latest/security/cert_manager_operator/index.html
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_22014.json