Skip to main content
EPSS 1.1%top 36%

Red Hat Security Advisory: RHODF-4.16-RHEL-9 security update

0
High
Published: 06/04/2025 (06/04/2025, 01:58:44 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift DataFoundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API. Security Fix(es): * express: cause malformed URLs to be evaluated (CVE-2024-29041) * nodejs-async: Regular expression denial of service while parsing function in autoinject (CVE-2024-39249) * body-parser: Denial of Service Vulnerability in body-parser (CVE-2024-45590) * npm-serialize-javascript: Cross-site Scripting (XSS) in serialize-javascript (CVE-2024-11831) * http-proxy-middleware: Denial of Service (CVE-2024-21536) * golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338) * golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing (CVE-2025-30204) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected software

Affected versions
>=4.16 <4.17>=4.5 <4.5.6Red HatRed Hat OpenShift Data FoundationRHODF 4.16 for RHEL 9ppc64leodf4/cephcsi-rhel9@sha256:9e722e6ef66d768ad25c4029a6f4796b3035a8e0bcab1eea3b0b9e3e0ac80a2c_ppc64leRed Hat Advanced Cluster Security for KubernetesRHACS 4.5 for RHEL 8advanced-cluster-security/rhacs-central-db-rhel8@sha256:d42f1ed5f7e32313c51f59b5e10d2bafba6c51c3f47a53cec92b3bfeefca9e3c_ppc64le

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 18:07:12 UTC

Technical Analysis

This Red Hat security advisory covers multiple vulnerabilities fixed in Red Hat OpenShift Data Foundation 4.16 for RHEL 9 and Red Hat Advanced Cluster Security (RHACS) 4.5 for RHEL 8. Key fixes include CVE-2024-11831, a cross-site scripting vulnerability in the npm serialize-javascript package; CVE-2024-45590 and CVE-2024-21536, denial of service vulnerabilities in body-parser and http-proxy-middleware respectively; CVE-2024-39249, a regular expression denial of service in nodejs-async; CVE-2024-29041, an issue causing malformed URLs to be evaluated in express; and CVE-2024-45338, a non-linear parsing vulnerability in golang.org/x/net/html. Additionally, CVE-2025-30204 addresses excessive memory allocation during JWT header parsing in golang-jwt/jwt. The advisory provides updated images and patches for these issues. The vendor rates the update as Important and provides official fixes. No known exploits in the wild have been reported at this time.

Potential Impact

The vulnerabilities fixed in this update include cross-site scripting (XSS), denial of service (DoS), and memory allocation issues that could allow attackers to disrupt service availability or execute malicious scripts. The XSS vulnerability (CVE-2024-11831) could enable injection of malicious scripts in affected components. DoS vulnerabilities (e.g., CVE-2024-45590, CVE-2024-21536, CVE-2024-39249) could allow attackers to cause service interruptions by exploiting parsing or processing flaws. Memory allocation issues (CVE-2025-30204) could lead to resource exhaustion. These impacts affect the security and reliability of Red Hat OpenShift Data Foundation and Red Hat Advanced Cluster Security products.

Mitigation Recommendations

Red Hat has released official fixes for all identified vulnerabilities in updated versions of Red Hat OpenShift Data Foundation 4.16 for RHEL 9 and Red Hat Advanced Cluster Security 4.5 for RHEL 8. Users are strongly advised to apply these security updates promptly by following the vendor's guidance at https://access.redhat.com/articles/11258 and the respective advisory pages. The vendor manages remediation through updated images and patches. No additional mitigation steps are required beyond applying the official updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:8479
Cve Count
7
Additional Cves
["CVE-2024-21536","CVE-2024-29041","CVE-2024-39249","CVE-2024-45338","CVE-2024-45590","CVE-2025-30204"]
Cvss Version
3.1

Threat ID: 6a160971e29bf47b50638f49

Added to database: 05/26/2026, 20:58:25 UTC

Last enriched: 08/10/2026, 18:07:12 UTC

Last updated: 09/10/2026, 22:04:10 UTC

Views: 131

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses