Skip to main content
EPSS 1.3%top 32%

Red Hat Security Advisory: OpenShift Container Platform 4.16.14 security update

0
Medium
Published: 09/24/2024 (09/24/2024, 15:28:01 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. Security Fix(es): * containers/image: digest type does not guarantee valid type (CVE-2024-3727) * golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON (CVE-2024-24786) * Bare Metal Operator: BMO can expose particularly named secrets from other namespaces via BMH CRD (CVE-2024-43803) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected software

Affected versions
>=4.16.0 <4.16.14>=4.4.0 <4.4.5Red HatRed Hat OpenShift EnterpriseRed Hat OpenShift Container Platform 4.16srcOpenShift VirtualizationCNV 4.15 for RHEL 9amd64container-native-virtualization/aaq-controller-rhel9@sha256:a3be4be46dbde0a95596ccd5a8039d4bad56e014aa0120e8032423be6c16615a_amd64openshift4/ose-cluster-monitoring-rhel9-operator@sha256:993d06c62de4e6a6eefed9eb2a475a53cbb0431ff278ba1df1c33389626d7966_amd64OpenShift API for Data Protection9Base-OADP-1.3ppc64leoadp/oadp-kubevirt-velero-plugin-rhel9@sha256:6818ab81497735d1ccaebd8814af9104260eb4c5ce484320c19b01d0bc2427d2_ppc64learm64openshift4/ose-cluster-autoscaler-rhel9@sha256:d2f5505862a7f14285ef251ffb56fd57c673bdac15233eea16dcb32e357dddf2_arm64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 22:34:47 UTC

Technical Analysis

This security advisory covers multiple vulnerabilities fixed in Red Hat OpenShift Container Platform 4.16.14 and Red Hat Advanced Cluster Security (RHACS) 4.4.5. Notably, CVE-2024-3727 addresses a flaw in the containers/image component where the digest type does not guarantee a valid type, potentially affecting image validation processes. Additional vulnerabilities fixed include an infinite loop in protojson.Unmarshal when processing certain invalid JSON (CVE-2024-24786) and a Bare Metal Operator issue exposing secrets across namespaces (CVE-2024-43803). The updates include patched packages and container images for multiple architectures. The vendor advisory confirms these fixes and provides upgrade instructions and image digests for verification.

Potential Impact

The vulnerabilities fixed in this update have a moderate security impact as rated by Red Hat Product Security. Issues include potential improper validation of container image digests, infinite loops in JSON unmarshaling that could cause denial of service, and unauthorized exposure of secrets via the Bare Metal Operator. These could affect the integrity and confidentiality of container workloads and cluster operations if exploited. No known exploits in the wild have been reported at this time.

Mitigation Recommendations

Red Hat has released OpenShift Container Platform 4.16.14 and RHACS 4.4.5 containing fixes for these vulnerabilities. Users should upgrade to these versions as soon as possible following the vendor's documented upgrade procedures. The vendor manages remediation for these on-premise/private cloud deployments; no additional mitigation steps are indicated beyond applying the official updates. Refer to the Red Hat advisory and OpenShift documentation for detailed upgrade instructions and image verification.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2024:6824
Cve Count
3
Additional Cves
["CVE-2024-24786","CVE-2024-43803"]
Cvss Version
3.1

Threat ID: 6a160958e29bf47b5061fc1a

Added to database: 05/26/2026, 20:58:00 UTC

Last enriched: 08/14/2026, 22:34:47 UTC

Last updated: 09/10/2026, 19:36:48 UTC

Views: 95

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses