Skip to main content
EPSS 8.8%top 5.1%

Red Hat Security Advisory: OpenShift Compliance Operator bug fix and enhancement update

0
High
Published: 11/20/2025 (11/20/2025, 19:56:52 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

The OpenShift Compliance Operator v1.8.0 is now available. See the documentation for bug fix information: https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/security_and_compliance/compliance-operator#compliance-operator-release-notes

Affected software

Affected versions
>=4.14.0 <4.14.48Red HatRed Hat OpenShift EnterpriseRed Hat OpenShift Container Platform 4.14arm640OpenShift Compliance OperatorOpenShift Compliance Operator 1amd64registry.redhat.io/compliance/openshift-compliance-operator-bundle@sha256:0bc0b7a20ce3c6303a45a699f44d2b90597b6a62846e89a5bca285b3228a9a52_amd64Red Hat Enterprise LinuxRed Hat Enterprise Linux AppStream (v. 9)Red Hat Enterprise Linux BaseOS (v. 9)srcCompliance OperatorCompliance Operator 1

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 20:51:11 UTC

Technical Analysis

This Red Hat security advisory covers OpenShift Container Platform 4.14.48, which contains updated container images and packages that fix multiple security vulnerabilities. Notably, it addresses CVE-2024-12085, an information leak via uninitialized stack contents in rsync, and CVE-2024-45337, an authorization bypass due to misuse of ServerConfig.PublicKeyCallback in golang.org/x/crypto/ssh. Additional fixes include a non-linear parsing issue in golang.org/x/net/html and a kernel media driver fix (uvcvideo). The advisory provides updated images for multiple architectures and instructs users to upgrade using the OpenShift CLI or web console. The update is rated as having an important security impact by Red Hat Product Security.

Potential Impact

The vulnerabilities fixed in this update could lead to information disclosure (rsync info leak) and potential authorization bypass (golang.org/x/crypto/ssh). These issues may allow attackers to gain unauthorized access or leak sensitive information if exploited. The update mitigates these risks by correcting the underlying flaws in the affected components. No known exploits in the wild have been reported at the time of this advisory.

Mitigation Recommendations

A fix is available in Red Hat OpenShift Container Platform version 4.14.48. Users should upgrade to this version using the OpenShift CLI (oc) or web console as soon as the update is available in their release channel. Detailed upgrade instructions are provided in the official Red Hat documentation. No additional mitigation steps are indicated beyond applying this update.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:1451
Cve Count
4
Additional Cves
["CVE-2024-45337","CVE-2024-45338","CVE-2024-53104"]
Cvss Version
3.1

Threat ID: 6a18be67e29bf47b50388239

Added to database: 05/28/2026, 22:15:03 UTC

Last enriched: 08/10/2026, 20:51:11 UTC

Last updated: 09/10/2026, 19:36:47 UTC

Views: 166

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses