Skip to main content
EPSS 0.3%top 76%

Red Hat Security Advisory: OpenShift Container Platform 4.16.45 bug fix and security update

0
High
Published: 07/30/2025 (07/30/2025, 13:13:16 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.16.45. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2025:11682 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ Security Fix(es): * github.com/golang/glog: Vulnerability when creating log files in github.com/golang/glog (CVE-2024-45339) * podman: podman missing TLS verification (CVE-2025-6032) * jq: AddressSanitizer: stack-buffer-overflow in jq_fuzz_execute (jv_string_vfmt) (CVE-2025-48060) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli.

Affected software

Affected versions
>=4.20.0 <4.21.0Red HatRed Hat OpenShift Container PlatformRed Hat OpenShift Container Platform 4.20amd64registry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9@sha256:1583cfb844b724795aca35db8c9ed9fbe84b99458dc3fb706d87046e55290e17_amd64Red Hat OpenShift EnterpriseRed Hat OpenShift Container Platform 4.16ppc64leopenshift4/ose-cluster-autoscaler-rhel9@sha256:a642b9ca8a251150741207528d01627017f2b93d10247763373e15c208efa1c0_ppc64leRed Hat OpenShift Container Platform 4.2Red Hat OpenShift Container Platform 4.14registry.redhat.io/openshift4/lifecycle-agent-rhel9-operator@sha256:9d9db89434482e948a42d0bb3b7650322d8fcd8ba2c3ac8d59b698c85f2b3114_amd64Red Hat OpenShift Container Platform 4.18registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:94a7a1e65fc53c4dd51546879ef4350a55ba784758228fcae8787756480936e0_ppc64leregistry.redhat.io/openshift4/cloud-event-proxy-rhel8@sha256:18032f7dd2ce8f5bf3df51c3888e3d7ddf2f182b77ddd2d0b644742e640432a0_amd64Red Hat OpenShift Container Platform 4.17registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:9fa94690981b45ffc7279dd9fa37001d2e39089dbd723c48c04412404cb56f6b_amd64Red Hat OpenShift Container Platform 4.19openshift4/ose-cluster-autoscaler-rhel9@sha256:ebcacdc89813f025c08de45f8f08e1820677dba3f1b3f457bcafdf5c43be03ed_amd64registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:d848a2e05ee2ceb81d9268087ec3bdc7ff156b07e17a626c6134f62429092f51_ppc64leRed Hat OpenShift Container Platform 4.15registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:2aef783b18def6dcf5f0c6caaf23560b520358a2192fb11df61b9d22c427e820_amd64registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:c441ad0b361c9b20f5dfe418f5ec3f36c61366a9dad0df3829acea20ac7bab52_amd64Red Hat OpenShift Container Platform 4.12registry.redhat.io/openshift4/cloud-event-proxy-rhel8@sha256:f1c435c1032a92ae1990e412713d491096f31ed5bbb44d45f476e506fc13950d_amd64OpenShift Developer Tools and ServicesOpenShift Developer Tools and Services for OCP 4.12srcjenkins-2-plugins-0:4.12.1740464689-1.el8.srcarm64openshift4/ose-cloud-event-proxy-rhel9@sha256:d9932850f206c162c11db1eea3c1ab7561e6efbb9d1d724675f063528b1ba73a_arm64registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:8999b598396034adb806e5b7b4edc14299a22245a306ebe0d4a9bb9080765237_arm64Red Hat OpenShift Container Platform 4.13registry.redhat.io/openshift4/ose-cloud-event-proxy@sha256:5be9f7bd786c6a7771b91ae12a084f6e08d9809fd4051278c6db7451d54297b9_amd64registry.redhat.io/openshift4/ose-csi-external-resizer-rhel9@sha256:046025c626880357c668bbc55f96565f82cbe3fad509b4c9ac94f83576b9f3df_ppc64leregistry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:73f05204ce4f19a107ad62ae65897b2ec9f6d255aea083ca3c129056a2334d7f_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 22:28:40 UTC

Technical Analysis

This Red Hat security advisory for OpenShift Container Platform 4.20.0 addresses several security issues, notably CVE-2024-45339, a vulnerability in the golang.org/x/glog logging library. The flaw allows local attackers with low privileges to overwrite sensitive files by exploiting predictable log file paths and planting symbolic links in writable directories, potentially leading to confidentiality and integrity breaches. The advisory also includes fixes for other vulnerabilities such as node pull credential overwriting and Helm chart code execution. The update includes new container images and RPM packages. Red Hat rates the overall security impact as Important (high severity) and provides detailed upgrade instructions. No known exploits are reported in the wild at this time.

Potential Impact

The primary impact of CVE-2024-45339 is that an attacker with local access and low privileges can overwrite sensitive files by exploiting symbolic link vulnerabilities in the logging process, potentially leading to unauthorized modification or bypass of security mechanisms. This can compromise confidentiality and integrity of the system. Other addressed vulnerabilities in this update also pose risks such as credential overwriting and code execution. No availability impact is reported. No known active exploitation has been observed.

Mitigation Recommendations

A fix is available through updated container images and RPM packages included in Red Hat OpenShift Container Platform 4.20.0. Users should upgrade to these updated packages and images via the official release channels using the OpenShift CLI (oc) or web console. Detailed upgrade instructions are provided by Red Hat in their documentation. No alternative mitigations meeting Red Hat's criteria are currently available for CVE-2024-45339. Applying the official update is the recommended remediation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:9562
Cve Count
4
Additional Cves
["CVE-2024-45497","CVE-2025-22869","CVE-2025-53547"]

Threat ID: 6a160970e29bf47b5063853d

Added to database: 05/26/2026, 20:58:24 UTC

Last enriched: 08/14/2026, 22:28:40 UTC

Last updated: 09/10/2026, 19:36:48 UTC

Views: 185

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2025:9562https://access.redhat.com/security/cve/CVE-2024-45339https://access.redhat.com/security/cve/CVE-2024-45497https://access.redhat.com/security/cve/CVE-2025-22869https://access.redhat.com/security/cve/CVE-2025-53547https://access.redhat.com/security/updates/classification/Canonical URLhttps://access.redhat.com/errata/RHSA-2025:14821Canonical URLhttps://access.redhat.com/errata/RHSA-2025:16161Canonical URLhttps://access.redhat.com/errata/RHSA-2025:11673https://access.redhat.com/security/updates/classification/#important23424632372406OCPBUGS-56253OCPBUGS-56733OCPBUGS-58285OCPBUGS-58400OCPBUGS-58433OCPBUGS-59254OCPBUGS-59315OCPBUGS-59398OCPBUGS-59493OCPBUGS-59513Canonical URLhttps://access.redhat.com/errata/RHSA-2025:14856Canonical URLhttps://access.redhat.com/errata/RHSA-2025:19356Canonical URLhttps://access.redhat.com/errata/RHSA-2025:222323164212324606232603423260432326047Canonical URLhttps://access.redhat.com/errata/RHSA-2025:11675OCPBUGS-59179OCPBUGS-59200OCPBUGS-59561Canonical URLhttps://access.redhat.com/errata/RHSA-2025:1167723678422372501OCPBUGS-54314OCPBUGS-56167OCPBUGS-56995OCPBUGS-57068OCPBUGS-57782OCPBUGS-57887OCPBUGS-57949OCPBUGS-58203OCPBUGS-58280OCPBUGS-58366OCPBUGS-58457OCPBUGS-59235OCPBUGS-59260OCPBUGS-59280OCPBUGS-59421https://access.redhat.com/errata/RHSA-2025:11681OCPBUGS-36677OCPBUGS-54316OCPBUGS-54752OCPBUGS-56838OCPBUGS-56992OCPBUGS-58133OCPBUGS-58161OCPBUGS-58290OCPBUGS-58509OCPBUGS-59274OCPBUGS-59445Canonical URLhttps://access.redhat.com/errata/RHSA-2025:16526Canonical URLhttps://access.redhat.com/errata/RHSA-2025:14061Canonical URLhttps://access.redhat.com/errata/RHSA-2025:14398Canonical URLhttps://access.redhat.com/errata/RHSA-2025:13849Canonical URLhttps://access.redhat.com/errata/RHSA-2025:132892374692OCPBUGS-59791OCPBUGS-59872Canonical URLhttps://access.redhat.com/errata/RHSA-2025:14860Canonical URLhttps://access.redhat.com/errata/RHSA-2025:17672Canonical URLhttps://access.redhat.com/errata/RHSA-2025:15674Canonical URLhttps://access.redhat.com/errata/RHSA-2025:9563Canonical URLhttps://access.redhat.com/errata/RHSA-2025:11679Canonical URLhttps://access.redhat.com/errata/RHSA-2025:15333Canonical URLhttps://access.redhat.com/errata/RHSA-2025:19357Canonical URLhttps://access.redhat.com/errata/RHSA-2025:16527Canonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses