(RHSA-2025:4018) Important: OpenShift Container Platform 4.18.10 security and extras update

Vulnerability Details

Basic Information

Title (RHSA-2025:4018) Important: OpenShift Container Platform 4.18.10 security and extras update
Type redhat
Published 2025-04-22T13:09:39
Last Seen 2025-04-22T17:11:54
CVSS Score 7.3 (HIGH)

CVSS v3 Details

Attack Vector LOCAL
Attack Complexity LOW
Privileges Required LOW
User Interaction REQUIRED
Scope UNCHANGED
Confidentiality Impact HIGH
Integrity Impact HIGH
Availability Impact HIGH

CVE Information

CVE IDs CVE-2025-27516
CWE CWE-1336
Bulletin Family unix

Description

Red Hat OpenShift Container Platform is Red Hat’s cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.18.10. See the following advisory for the container images for this release:

https://access.redhat.com/errata/RHSA-2025:4019

Security Fix(es):

* jinja2: Jinja sandbox breakout through attr filter selecting format
method (CVE-2025-27516)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli.

Impact Assessment

Base Score 7.3
Severity HIGH

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.