Red Hat released OpenShift Container Platform 4.17.7 with updated RPM packages and images to remediate CVE-2023-44270, a moderate-severity improper input-validation vulnerability in PostCSS. The flaw can cause CSS placed inside comments to be interpreted as active code; an attacker able to supply untrusted CSS could cause PostCSS to emit malicious elements and compromise rendered page integrity.
Red Hat rated the issue CVSS 5.3 and said no mitigation is known beyond avoiding the parsing of untrusted CSS with PostCSS. The update applies to OpenShift 4.17 deployments on RHEL 8 and RHEL 9 for x86_64, ppc64le, s390x, and aarch64; administrators should upgrade clusters through the appropriate OpenShift release channel using the web console or OpenShift CLI.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2025:1249, which fixes CVE-2023-44270 in the discovery-server-rhel9 and discovery-ui-rhel9 components of Discovery 1 for RHEL 9.
Red Hat released RHSA-2025:0654, fixing CVE-2023-44270 for the ose-networking-console-plugin-rhel9 component in OpenShift Container Platform 4.17.
Red Hat published RHSA-2024:10517 for OpenShift Container Platform 4.17.7, providing updated RPM packages and images that remediate CVE-2023-44270 in PostCSS. The Moderate-severity advisory applies to OpenShift 4.17 deployments on RHEL 8 and RHEL 9 across supported architectures.
Red Hat lists RHSA-2024:6121 as fixing CVE-2023-44270 in several OpenShift Container Platform 4.18 RHEL 9 components, including ingress-node-firewall, kube-compare-artifacts, kubernetes-nmstate, and MetalLB packages and operators.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.