Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.18 security, enhancement & bug fix update

0
High
Published: Mon Dec 22 2025 (12/22/2025, 14:47:09 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift Data Foundation 4. 18 has a security advisory addressing two vulnerabilities identified as CVE-2025-30204 and CVE-2025-47907. The advisory is classified as important and relates to security, enhancement, and bug fixes. No explicit patch or fix details are provided in the advisory content. The vulnerabilities are associated with CWE-405 (missing or incorrect permission) and CWE-362 (race condition). There are no known exploits in the wild at the time of publication. Users are advised to apply this update after ensuring all previous relevant errata have been applied. The advisory does not specify affected countries or targeted regions.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/27/2026, 00:18:29 UTC

Technical Analysis

This security advisory from Red Hat Product Security concerns Red Hat OpenShift Data Foundation 4.18 and addresses two vulnerabilities: CVE-2025-30204 and CVE-2025-47907. The vulnerabilities relate to permission issues and race conditions (CWE-405 and CWE-362). The advisory notes a security, enhancement, and bug fix update but does not detail specific fixes or patches within the provided content. There are no known exploits reported in the wild. The update requires prior application of all previous relevant errata. The advisory references multiple container images and components related to OpenShift Data Foundation but does not provide explicit remediation steps or patch availability.

Potential Impact

The vulnerabilities are rated as high severity and involve potential security weaknesses related to improper permissions and race conditions. These could potentially allow unauthorized actions or inconsistent system states if exploited. However, no known active exploitation has been reported. The impact is limited to affected versions of Red Hat OpenShift Data Foundation 4.18 and related components. Without detailed exploit information or confirmed active attacks, the practical impact remains theoretical but significant given the high severity rating.

Mitigation Recommendations

The vendor advisory instructs users to apply the update after ensuring all previously released errata relevant to their system have been applied. No explicit patch or fix details are provided in the advisory content, so patch status is not yet confirmed. Users should monitor the official Red Hat advisory page for updates and follow the documented update procedures at https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.18/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf. Since this is not a cloud service, remediation depends on applying vendor updates. No vendor statement indicates that no action is required or that the issue is already mitigated.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:23916
Cve Count
2
Additional Cves
["CVE-2025-47907"]
Cvss Version
null

Threat ID: 6a160974e29bf47b5063d54c

Added to database: 5/26/2026, 8:58:28 PM

Last enriched: 5/27/2026, 12:18:29 AM

Last updated: 5/27/2026, 5:03:34 AM

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses