Red Hat issued Important security updates for OpenShift Container Platform (OCP) 4.15, 4.16, and 4.17, delivering updated container images and packages across supported RHEL 8 and RHEL 9 deployments and x86_64, s390x, ppc64le, and aarch64 systems. OCP 4.15.44 fixes CVE-2023-6597, a Python tempfile.TemporaryDirectory path-traversal issue, and CVE-2024-45338, a non-linear parsing flaw in golang.org/x/net/html.
OCP 4.16.42 and 4.17.32 address an OpenShift Console server-side request forgery (SSRF) flaw, alongside Go dependency issues involving OAuth2 JWS parsing memory consumption, HTML parsing, and zlib pointer arithmetic. Separately, OCP 4.17.26 remediates CVE-2025-22869 in golang.org/x/crypto/ssh, CVE-2025-30204 in jwt-go header parsing, and CVE-2024-53150, an out-of-bounds read in the Linux kernel ALSA USB-audio handling. Red Hat recommends affected customers upgrade through their applicable OpenShift release channel using the CLI or web console.

See affected versions and whether adversaries are exploiting it.
19 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated RHSA-2025:8556, releasing OpenShift Container Platform 4.16.42. The update addressed OpenShift Console SSRF (CVE-2024-6538) and vulnerabilities in golang.org/x/net/html, golang.org/x/oauth2/jws, and golang-jwt/jwt.
Red Hat issued Important-rated RHSA-2025:8280 for OpenShift Container Platform 4.17.32. It fixed an OpenShift Console SSRF flaw (CVE-2024-6538), Go parsing and memory-consumption flaws, and CVE-2016-9840 in zlib.
Red Hat issued Important-rated advisory RHSA-2025:0646, releasing OpenShift Container Platform 4.15.44. The update remediated CVE-2023-6597 in Python tempfile.TemporaryDirectory and CVE-2024-45338 in golang.org/x/net/html.
Red Hat issued Important-rated advisory RHSA-2025:0364, releasing OpenShift Container Platform 4.14.45 container images. The update remediated the Python tempfile.TemporaryDirectory path-traversal flaw CVE-2023-6597 and the golang.org/x/net/html parsing flaw CVE-2024-45338.
Red Hat issued Important-rated advisory RHSA-2024:9620, releasing OpenShift Container Platform 4.14.41 container images. The update fixed OpenShift Console OAuth2 state-parameter entropy CVE-2024-6508, QEMU NBD denial-of-service CVE-2024-7409, and DOMPurify flaws CVE-2024-47875 and CVE-2024-48910; it also corrected a libreswan downgrade in 4.14.40 that introduced CVE exposure.
Red Hat issued Important-rated advisory RHSA-2024:8981 for OpenShift Container Platform 4.17.4. The update provided container images fixing Axios SSRF CVE-2024-39338, DOMPurify mutation XSS CVE-2024-47875, and numerous additional vulnerabilities and platform issues.
Red Hat issued Important-rated advisory RHSA-2024:6004, releasing OpenShift Container Platform 4.16.10 container images. The update fixed denial-of-service flaws in Go, golang-protobuf, and BIND 9, plus a go-retryablehttp issue that could expose sensitive URL information in logs.
Red Hat issued Important-rated advisory RHSA-2024:5422 for OpenShift Container Platform 4.16.8. The update fixed Linux kernel route-management use-after-free CVE-2024-36971, golang-protobuf invalid-JSON infinite-loop CVE-2024-24786, and additional listed vulnerabilities.
Red Hat issued Important-rated RHSA-2024:4456 for RHEL 8.4 Extended Life Cycle Long Life, AUS, TUS, and SAP update-service offerings. The python3-3.6.8-39.el8_4.5 update remediated the Python tempfile.TemporaryDirectory path-traversal vulnerability, CVE-2023-6597.
Red Hat issued Important-rated RHSA-2024:4166 for python3 in Red Hat Enterprise Linux Server Advanced Update Support 8.2. The update supplied Python 3.6.8-24.el8_2.3 packages and remediated the tempfile.TemporaryDirectory path-traversal vulnerability, CVE-2023-6597.
Red Hat issued Important-rated RHSA-2024:4058 for python3.11 on Red Hat Enterprise Linux 8 and RHEL 8.10 Extended Life Cycle. The python3.11-3.11.9-1.el8_10 update remediated tempfile.TemporaryDirectory path traversal CVE-2023-6597 and ZIP-bomb denial of service CVE-2024-0450.
Red Hat issued Important-rated RHSA-2024:3466 for Red Hat Enterprise Linux 8 python39:3.9 and python39-devel:3.9 modules. The update fixed CVE-2023-6597, Python zip-bomb denial of service CVE-2024-0450, and python-idna resource-consumption flaw CVE-2024-3651.
Red Hat released RHSA-2024:3347 to fix the CPython tempfile.TemporaryDirectory symlink-dereference vulnerability, CVE-2023-6597, in Red Hat Enterprise Linux 8 python3. Red Hat subsequently issued fixes for additional RHEL 8 Python versions and supported update streams through July 2024.
Red Hat addressed CVE-2024-6508, an OpenShift Console OAuth 2.0 state-parameter entropy weakness that could enable CSRF and account-linking attacks, through advisories for OpenShift Container Platform 4.12 through 4.17. The fixes included RHSA-2024:7922, RHSA-2024:8415, RHSA-2024:8991, RHSA-2024:9620, RHSA-2024:10813, and RHSA-2025:0014.
Red Hat issued Important-rated advisory RHSA-2025:1120 for OpenShift Container Platform 4.17.16. The update remediated CVE-2023-6597, rsync information-disclosure flaw CVE-2024-12085, golang.org/x/net/html flaw CVE-2024-45338, and Unbound denial-of-service flaw CVE-2024-8508.
Red Hat released Important-rated advisory RHSA-2024:8415 for OpenShift Container Platform 4.16.19, providing updated packages and container images. The update fixed insufficient OAuth2 state-parameter entropy in openshift-console (CVE-2024-6508), a golang-protobuf invalid-JSON infinite-loop flaw (CVE-2024-24786), and missing image checksum validation in openstack-ironic (CVE-2024-47211).
Red Hat addressed the authenticated OpenShift Console SSRF vulnerability, CVE-2024-6538, in OpenShift Container Platform 4.18 through advisory RHSA-2025:7863. The flaw allowed authenticated users to make attacker-controlled HTTP(S) requests from the Console pod to internally reachable services.
Red Hat released an Important-rated OpenShift Container Platform 4.17.26 bug-fix and security update. It remediated denial of service in golang.org/x/crypto/ssh (CVE-2025-22869), excessive JWT-header allocation (CVE-2025-30204), and Linux kernel ALSA USB-audio out-of-bounds reads (CVE-2024-53150).
Red Hat issued advisories between January and March 2025 to remediate the CPython tempfile.TemporaryDirectory symlink-dereference flaw, CVE-2023-6597, in OpenShift Container Platform releases 4.12 through 4.18. The flaw could allow a user able to run a privileged program to alter permissions on files referenced through symbolic links under certain conditions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
22 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.