CVE Vulnerabilities

CVE-2025-30204

Asymmetric Resource Consumption (Amplification)

Published: Mar 21, 2025 | Modified: Apr 10, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

golang-jwt is a Go implementation of JSON Web Tokens. Starting in version 3.2.0 and prior to versions 5.2.2 and 4.5.2, the function parse.ParseUnverified splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result, in the face of a malicious request whose Authorization header consists of Bearer followed by many period characters, a call to that function incurs allocations to the tune of O(n) bytes (where n stands for the length of the functions argument), with a constant factor of about 16. This issue is fixed in 5.2.2 and 4.5.2.

Weakness

The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary’s influence is “asymmetric.”

Affected Software

Name Vendor Start Version End Version
Cryostat 4 on RHEL 9 RedHat cryostat/cryostat-agent-init-rhel9:0.5.0-9 *
Cryostat 4 on RHEL 9 RedHat cryostat/cryostat-db-rhel9:4.0.0-10 *
Cryostat 4 on RHEL 9 RedHat cryostat/cryostat-grafana-dashboard-rhel9:4.0.0-10 *
Cryostat 4 on RHEL 9 RedHat cryostat/cryostat-openshift-console-plugin-rhel9:4.0.0-10 *
Cryostat 4 on RHEL 9 RedHat cryostat/cryostat-operator-bundle:4.0.0-9 *
Cryostat 4 on RHEL 9 RedHat cryostat/cryostat-ose-oauth-proxy-rhel9:4.0.0-10 *
Cryostat 4 on RHEL 9 RedHat cryostat/cryostat-reports-rhel9:4.0.0-10 *
Cryostat 4 on RHEL 9 RedHat cryostat/cryostat-rhel9:4.0.0-10 *
Cryostat 4 on RHEL 9 RedHat cryostat/cryostat-rhel9-operator:4.0.0-10 *
Cryostat 4 on RHEL 9 RedHat cryostat/cryostat-storage-rhel9:4.0.0-10 *
Cryostat 4 on RHEL 9 RedHat cryostat/jfr-datasource-rhel9:4.0.0-10 *
Multicluster engine for Kubernetes 2.5 for RHEL 8 RedHat multicluster-engine/agent-service-rhel8:v2.5.9-8 *
Multicluster engine for Kubernetes 2.5 for RHEL 8 RedHat multicluster-engine/assisted-image-service-rhel8:v2.5.9-7 *
Multicluster engine for Kubernetes 2.5 for RHEL 8 RedHat multicluster-engine/assisted-installer-agent-rhel8:v2.5.9-8 *
Multicluster engine for Kubernetes 2.5 for RHEL 8 RedHat multicluster-engine/assisted-installer-reporter-rhel8:v2.5.9-8 *
Multicluster engine for Kubernetes 2.5 for RHEL 8 RedHat multicluster-engine/assisted-installer-rhel8:v2.5.9-8 *
Multicluster engine for Kubernetes 2.5 for RHEL 8 RedHat multicluster-engine/hive-rhel8:v2.5.9-9 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/addon-manager-rhel9:v2.5.9-12 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/apiserver-network-proxy-rhel9:v2.5.9-6 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/aws-encryption-provider-rhel9:v2.5.9-6 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/backplane-rhel9-operator:v2.5.9-13 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/cluster-api-provider-agent-rhel9:v2.5.9-6 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/cluster-api-provider-aws-rhel9:v2.5.9-6 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/cluster-api-provider-kubevirt-rhel9:v2.5.9-7 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/cluster-api-rhel9:v2.5.9-6 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/clusterclaims-controller-rhel9:v2.5.9-8 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/cluster-curator-controller-rhel9:v2.5.9-9 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/cluster-image-set-controller-rhel9:v2.5.9-7 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/clusterlifecycle-state-metrics-rhel9:v2.5.9-8 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/cluster-proxy-addon-rhel9:v2.5.9-9 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/cluster-proxy-rhel9:v2.5.9-10 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/console-mce-rhel9:v2.5.9-11 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/discovery-rhel9:v2.5.9-10 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/hypershift-addon-rhel9-operator:v2.5.9-7 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/hypershift-cli-rhel9:v2.5.9-9 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/hypershift-rhel9-operator:v2.5.9-10 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/image-based-install-rhel9:v2.5.9-32 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/klusterlet-operator-bundle:v2.5.9-12 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/kube-rbac-proxy-mce-rhel9:v2.5.9-6 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/managedcluster-import-controller-rhel9:v2.5.9-9 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/managed-serviceaccount-rhel9:v2.5.9-11 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/mce-operator-bundle:v2.5.9-14 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/multicloud-manager-rhel9:v2.5.9-10 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/must-gather-rhel9:v2.5.9-13 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/placement-rhel9:v2.5.9-12 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/provider-credential-controller-rhel9:v2.5.9-8 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/registration-operator-rhel9:v2.5.9-12 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/registration-rhel9:v2.5.9-12 *
Multicluster engine for Kubernetes 2.5 for RHEL 9 RedHat multicluster-engine/work-rhel9:v2.5.9-12 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/acm-cluster-permission-rhel9:v2.10.8-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/acm-governance-policy-addon-controller-rhel9:v2.10.8-9 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/acm-governance-policy-framework-addon-rhel9:v2.10.8-9 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/acm-grafana-rhel9:v2.10.8-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/acm-must-gather-rhel9:v2.10.8-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/acm-operator-bundle:v2.10.8-14 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/acm-prometheus-config-reloader-rhel9:v2.10.8-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/acm-prometheus-rhel9:v2.10.8-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/acm-search-indexer-rhel9:v2.10.8-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/acm-search-v2-api-rhel9:v2.10.8-10 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/acm-search-v2-rhel9:v2.10.8-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/acm-volsync-addon-controller-rhel9:v2.10.8-10 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/cert-policy-controller-rhel9:v2.10.8-9 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/cluster-backup-rhel9-operator:v2.10.8-10 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/config-policy-controller-rhel9:v2.10.8-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/console-rhel9:v2.10.8-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/endpoint-monitoring-rhel9-operator:v2.10.8-10 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/governance-policy-propagator-rhel9:v2.10.8-9 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/grafana-dashboard-loader-rhel9:v2.10.8-10 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/iam-policy-controller-rhel9:v2.10.8-9 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/insights-client-rhel9:v2.10.8-12 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/insights-metrics-rhel9:v2.10.8-10 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/klusterlet-addon-controller-rhel9:v2.10.8-12 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/kube-rbac-proxy-rhel9:v2.10.8-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/kube-state-metrics-rhel9:v2.10.8-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/memcached-exporter-rhel9:v2.10.8-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/memcached-rhel9:v2.10.8-5 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/metrics-collector-rhel9:v2.10.8-12 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/multicloud-integrations-rhel9:v2.10.8-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/multiclusterhub-rhel9:v2.10.8-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/multicluster-observability-rhel9-operator:v2.10.8-10 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/multicluster-operators-application-rhel9:v2.10.8-9 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/multicluster-operators-channel-rhel9:v2.10.8-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/multicluster-operators-subscription-rhel9:v2.10.8-10 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/node-exporter-rhel9:v2.10.8-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/observatorium-rhel9:v2.10.8-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/observatorium-rhel9-operator:v2.10.8-10 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/prometheus-alertmanager-rhel9:v2.10.8-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/prometheus-rhel9:v2.10.8-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/rbac-query-proxy-rhel9:v2.10.8-10 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/search-collector-rhel9:v2.10.8-10 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/submariner-addon-rhel9:v2.10.8-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/thanos-receive-controller-rhel9:v2.10.8-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 RedHat rhacm2/thanos-rhel9:v2.10.8-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-cluster-permission-rhel9:v2.11.7-9 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-governance-policy-addon-controller-rhel9:v2.11.7-12 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-governance-policy-framework-addon-rhel9:v2.11.7-16 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-grafana-rhel9:v2.11.7-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-must-gather-rhel9:v2.11.7-15 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-operator-bundle:v2.11.7-37 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-prometheus-config-reloader-rhel9:v2.11.7-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-prometheus-rhel9:v2.11.7-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-search-indexer-rhel9:v2.11.7-12 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-search-v2-api-rhel9:v2.11.7-10 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-search-v2-rhel9:v2.11.7-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/acm-volsync-addon-controller-rhel9:v2.11.7-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/cert-policy-controller-rhel9:v2.11.7-12 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/cluster-backup-rhel9-operator:v2.11.7-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/config-policy-controller-rhel9:v2.11.7-11 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/console-rhel9:v2.11.7-16 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/endpoint-monitoring-rhel9-operator:v2.11.7-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/governance-policy-propagator-rhel9:v2.11.7-12 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/grafana-dashboard-loader-rhel9:v2.11.7-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/insights-client-rhel9:v2.11.7-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/insights-metrics-rhel9:v2.11.7-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/klusterlet-addon-controller-rhel9:v2.11.7-12 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/kube-rbac-proxy-rhel9:v2.11.7-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/kube-state-metrics-rhel9:v2.11.7-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/memcached-exporter-rhel9:v2.11.7-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/memcached-rhel9:v2.11.7-6 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/metrics-collector-rhel9:v2.11.7-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/multicloud-integrations-rhel9:v2.11.7-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/multiclusterhub-rhel9:v2.11.7-17 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/multicluster-observability-rhel9-operator:v2.11.7-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/multicluster-operators-application-rhel9:v2.11.7-9 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/multicluster-operators-channel-rhel9:v2.11.7-9 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/multicluster-operators-subscription-rhel9:v2.11.7-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/node-exporter-rhel9:v2.11.7-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/observatorium-rhel9:v2.11.7-10 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/observatorium-rhel9-operator:v2.11.7-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/prometheus-alertmanager-rhel9:v2.11.7-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/prometheus-rhel9:v2.11.7-8 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/rbac-query-proxy-rhel9:v2.11.7-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/search-collector-rhel9:v2.11.7-13 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/submariner-addon-rhel9:v2.11.7-16 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/thanos-receive-controller-rhel9:v2.11.7-7 *
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9 RedHat rhacm2/thanos-rhel9:v2.11.7-9 *
Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 RedHat rhacm2/lighthouse-agent-rhel9:v0.19.4-1 *
Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 RedHat rhacm2/lighthouse-coredns-rhel9:v0.19.4-1 *
Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 RedHat rhacm2/nettest-rhel9:v0.19.4-1 *
Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 RedHat rhacm2/subctl-rhel9:v0.19.4-1 *
Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 RedHat rhacm2/submariner-gateway-rhel9:v0.19.4-1 *
Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 RedHat rhacm2/submariner-globalnet-rhel9:v0.19.4-1 *
Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 RedHat rhacm2/submariner-operator-bundle:v0.19.4-1 *
Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 RedHat rhacm2/submariner-rhel9-operator:v0.19.4-1 *
Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 RedHat rhacm2/submariner-route-agent-rhel9:v0.19.4-1 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-central-db-rhel8:4.5.9-1 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-collector-rhel8:4.5.9-1 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-collector-slim-rhel8:4.5.9-1 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-main-rhel8:4.5.9-1 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-operator-bundle:4.5.9-1 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-rhel8-operator:4.5.9-1 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-roxctl-rhel8:4.5.9-1 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-scanner-db-rhel8:4.5.9-1 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-scanner-db-slim-rhel8:4.5.9-1 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-scanner-rhel8:4.5.9-1 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-scanner-slim-rhel8:4.5.9-1 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-scanner-v4-db-rhel8:4.5.9-1 *
Red Hat Advanced Cluster Security 4.5 RedHat advanced-cluster-security/rhacs-scanner-v4-rhel8:4.5.9-1 *
Red Hat Advanced Cluster Security 4.6 RedHat advanced-cluster-security/rhacs-central-db-rhel8:4.6.5-1 *
Red Hat Advanced Cluster Security 4.6 RedHat advanced-cluster-security/rhacs-collector-rhel8:4.6.5-1 *
Red Hat Advanced Cluster Security 4.6 RedHat advanced-cluster-security/rhacs-collector-slim-rhel8:4.6.5-1 *
Red Hat Advanced Cluster Security 4.6 RedHat advanced-cluster-security/rhacs-main-rhel8:4.6.5-1 *
Red Hat Advanced Cluster Security 4.6 RedHat advanced-cluster-security/rhacs-operator-bundle:4.6.5-1 *
Red Hat Advanced Cluster Security 4.6 RedHat advanced-cluster-security/rhacs-rhel8-operator:4.6.5-1 *
Red Hat Advanced Cluster Security 4.6 RedHat advanced-cluster-security/rhacs-roxctl-rhel8:4.6.5-1 *
Red Hat Advanced Cluster Security 4.6 RedHat advanced-cluster-security/rhacs-scanner-db-rhel8:4.6.5-1 *
Red Hat Advanced Cluster Security 4.6 RedHat advanced-cluster-security/rhacs-scanner-db-slim-rhel8:4.6.5-1 *
Red Hat Advanced Cluster Security 4.6 RedHat advanced-cluster-security/rhacs-scanner-rhel8:4.6.5-1 *
Red Hat Advanced Cluster Security 4.6 RedHat advanced-cluster-security/rhacs-scanner-slim-rhel8:4.6.5-1 *
Red Hat Advanced Cluster Security 4.6 RedHat advanced-cluster-security/rhacs-scanner-v4-db-rhel8:4.6.5-1 *
Red Hat Advanced Cluster Security 4.6 RedHat advanced-cluster-security/rhacs-scanner-v4-rhel8:4.6.5-1 *
Red Hat Advanced Cluster Security 4.7 RedHat advanced-cluster-security/rhacs-central-db-rhel8:4.7.2-2 *
Red Hat Advanced Cluster Security 4.7 RedHat advanced-cluster-security/rhacs-collector-rhel8:4.7.2-2 *
Red Hat Advanced Cluster Security 4.7 RedHat advanced-cluster-security/rhacs-main-rhel8:4.7.2-3 *
Red Hat Advanced Cluster Security 4.7 RedHat advanced-cluster-security/rhacs-operator-bundle:4.7.2-4 *
Red Hat Advanced Cluster Security 4.7 RedHat advanced-cluster-security/rhacs-rhel8-operator:4.7.2-1 *
Red Hat Advanced Cluster Security 4.7 RedHat advanced-cluster-security/rhacs-roxctl-rhel8:4.7.2-1 *
Red Hat Advanced Cluster Security 4.7 RedHat advanced-cluster-security/rhacs-scanner-db-rhel8:4.7.2-1 *
Red Hat Advanced Cluster Security 4.7 RedHat advanced-cluster-security/rhacs-scanner-db-slim-rhel8:4.7.2-1 *
Red Hat Advanced Cluster Security 4.7 RedHat advanced-cluster-security/rhacs-scanner-rhel8:4.7.2-2 *
Red Hat Advanced Cluster Security 4.7 RedHat advanced-cluster-security/rhacs-scanner-slim-rhel8:4.7.2-1 *
Red Hat Advanced Cluster Security 4.7 RedHat advanced-cluster-security/rhacs-scanner-v4-db-rhel8:4.7.2-1 *
Red Hat Advanced Cluster Security 4.7 RedHat advanced-cluster-security/rhacs-scanner-v4-rhel8:4.7.2-3 *
Red Hat Enterprise Linux 9 RedHat grafana-0:10.2.6-9.el9_5 *
Red Hat Enterprise Linux 9 RedHat opentelemetry-collector-0:0.107.0-10.el9_5 *
Red Hat Enterprise Linux 9 RedHat osbuild-composer-0:118.2-1.el9_5 *
Red Hat Enterprise Linux 9.2 Extended Update Support RedHat grafana-0:9.0.9-6.el9_2 *
Red Hat Enterprise Linux 9.2 Extended Update Support RedHat osbuild-composer-0:76.1-1.el9_2 *
Red Hat Enterprise Linux 9.4 Extended Update Support RedHat grafana-0:9.2.10-22.el9_4 *
Red Hat Enterprise Linux 9.4 Extended Update Support RedHat opentelemetry-collector-0:0.107.0-8.el9_4 *
Red Hat Enterprise Linux 9.4 Extended Update Support RedHat osbuild-composer-0:101.3-1.el9_4 *
Red Hat OpenShift Container Platform 4.14 RedHat openshift4/ose-azure-workload-identity-webhook-rhel8:v4.14.0-202504020335.p0.g2cb8201.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.14 RedHat openshift4/ose-cloud-credential-operator:v4.14.0-202504011810.p0.g07cf957.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.14 RedHat cluster-etcd-operator-container-v4.14.0-202504220036.p0.g9abf7d2.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.14 RedHat openshift4/ose-agent-installer-api-server-rhel8:v4.14.0-202504220036.p0.g98a41af.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.14 RedHat openshift4/ose-ibm-vpc-block-csi-driver-rhel8:v4.14.0-202504220036.p0.g2d2b5e9.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.14 RedHat openshift4/ose-ibm-vpc-node-label-updater-rhel8:v4.14.0-202504220036.p0.g4a6fcb6.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.15 RedHat ose-azure-workload-identity-webhook-container-v4.15.0-202504011136.p0.g5db478a.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.15 RedHat ose-cloud-credential-operator-container-v4.15.0-202504010836.p0.g7617717.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.16 RedHat openshift4/ose-ibm-vpc-block-csi-driver-rhel9:v4.16.0-202504141735.p0.g8283424.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat ose-aws-cluster-api-controllers-container-v4.16.0-202504120704.p0.gde46a7e.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat ose-azure-workload-identity-webhook-container-v4.16.0-202504120704.p0.g5b8d171.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat ose-cloud-credential-operator-container-v4.16.0-202504120704.p0.g9d4c863.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.17 RedHat openshift4/ose-azure-workload-identity-webhook-rhel9:v4.17.0-202504010735.p0.g6707f89.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.17 RedHat openshift4/ose-cloud-credential-rhel9-operator:v4.17.0-202504010735.p0.gb00cc87.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.17 RedHat openshift4/azure-kms-encryption-provider-rhel9:v4.17.0-202504091537.p0.gf1e56a2.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.17 RedHat openshift4/ose-agent-installer-node-agent-rhel9:v4.17.0-202504091537.p0.gded6f9d.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.17 RedHat openshift4/ose-aws-cluster-api-controllers-rhel9:v4.17.0-202504091537.p0.gd09f317.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.17 RedHat openshift4/ose-agent-installer-orchestrator-rhel9:v4.17.0-202504141437.p0.g6a8ebdd.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.17 RedHat openshift4/ose-ibm-vpc-block-csi-driver-rhel9:v4.17.0-202504141804.p0.g5f18d29.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.17 RedHat openshift4/ose-cluster-etcd-rhel9-operator:v4.17.0-202504212104.p0.g50f5541.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.18 RedHat openshift4/ose-aws-cluster-api-controllers-rhel9:v4.18.0-202504021503.p0.g59febef.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.18 RedHat openshift4/ose-azure-workload-identity-webhook-rhel9:v4.18.0-202504021503.p0.gf60e402.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.18 RedHat openshift4/ose-cloud-credential-rhel9-operator:v4.18.0-202504021503.p0.gce6f538.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.18 RedHat openshift4/azure-kms-encryption-provider-rhel9:v4.18.0-202504090803.p0.gc937080.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.18 RedHat openshift4/ose-agent-installer-node-agent-rhel9:v4.18.0-202504090803.p0.g3aeceb7.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.18 RedHat openshift4/ose-agent-installer-orchestrator-rhel9:v4.18.0-202504090803.p0.g9257597.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.18 RedHat openshift4/ose-powervs-machine-controllers-rhel9:v4.18.0-202504090803.p0.g10ac06f.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.18 RedHat openshift4/ose-ibm-vpc-block-csi-driver-rhel9:v4.18.0-202504151633.p0.g88d2a3f.assembly.stream.el9 *
Red Hat OpenShift Container Platform 4.18 RedHat openshift4/ose-cluster-etcd-rhel9-operator:v4.18.0-202504211234.p0.gb355afe.assembly.stream.el9 *
RHODF-4.18-RHEL-9 RedHat odf4/cephcsi-rhel9:v4.18.2-8 *
RHODF-4.18-RHEL-9 RedHat odf4/mcg-rhel9-operator:v4.18.2-5 *
RHODF-4.18-RHEL-9 RedHat odf4/rook-ceph-rhel9-operator:v4.18.2-9 *
RHOL-5.9-RHEL-9 RedHat cluster-logging-operator-container-v5.9.13-9 *
RHOL-5.9-RHEL-9 RedHat cluster-logging-operator-metadata-container-v5.9.13-22 *
RHOL-5.9-RHEL-9 RedHat log-file-metric-exporter-container-v1.1.0-346 *
RHOL-5.9-RHEL-9 RedHat logging-eventrouter-container-v0.4.0-363 *
RHOL-5.9-RHEL-9 RedHat logging-fluentd-container-v5.9.13-5 *
RHOL-5.9-RHEL-9 RedHat logging-loki-container-v3.3.2-36 *
RHOL-5.9-RHEL-9 RedHat logging-vector-container-v0.34.1-37 *
RHOL-5.9-RHEL-9 RedHat logging-view-plugin-container-v5.9.13-7 *
RHOL-5.9-RHEL-9 RedHat loki-operator-bundle-container-v5.9.13-20 *
RHOL-5.9-RHEL-9 RedHat loki-operator-container-v5.9.13-9 *
RHOL-5.9-RHEL-9 RedHat lokistack-gateway-container-v0.1.0-767 *
RHOL-5.9-RHEL-9 RedHat opa-openshift-container-v0.1.0-383 *
RHOL-6.0-RHEL-9 RedHat cluster-logging-operator-container-v6.0.7-3 *
RHOL-6.0-RHEL-9 RedHat cluster-logging-operator-metadata-container-v6.0.7-5 *
RHOL-6.0-RHEL-9 RedHat loki-operator-bundle-container-v6.0.7-8 *
RHOL-6.0-RHEL-9 RedHat loki-operator-container-v6.0.7-4 *
RHOL-6.0-RHEL-9 RedHat lokistack-gateway-container-v0.1.0-764 *
RHOL-6.0-RHEL-9 RedHat opa-openshift-container-v0.1.0-380 *
RHOL-6.0-RHEL-9 RedHat openshift-logging/eventrouter-rhel9:v0.4.0-357 *
RHOL-6.0-RHEL-9 RedHat openshift-logging/log-file-metric-exporter-rhel9:v1.1.0-338 *
RHOL-6.0-RHEL-9 RedHat openshift-logging/logging-loki-rhel9:v3.4.2-7 *
RHOL-6.0-RHEL-9 RedHat openshift-logging/vector-rhel9:v0.37.1-35 *
RHOL-6.1-RHEL-9 RedHat cluster-logging-operator-container-v6.1.5-4 *
RHOL-6.1-RHEL-9 RedHat cluster-logging-operator-metadata-container-v6.1.5-8 *
RHOL-6.1-RHEL-9 RedHat log-file-metric-exporter-container-v1.1.0-347 *
RHOL-6.1-RHEL-9 RedHat logging-loki-container-v3.4.2-11 *
RHOL-6.1-RHEL-9 RedHat logging-vector-container-v0.37.1-36 *
RHOL-6.1-RHEL-9 RedHat loki-operator-bundle-container-v6.1.5-10 *
RHOL-6.1-RHEL-9 RedHat loki-operator-container-v6.1.5-5 *
RHOL-6.1-RHEL-9 RedHat lokistack-gateway-container-v0.1.0-770 *
RHOL-6.1-RHEL-9 RedHat opa-openshift-container-v0.1.0-385 *
RHOL-6.1-RHEL-9 RedHat openshift-logging/eventrouter-rhel9:v0.4.0-365 *
Builds for Red Hat OpenShift 1.2.2 RedHat registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9:sha256:325c3c55e3942fb2e5fb1611366d3c0a82dabaa1017788226fda83eb553ef4e7 *
Builds for Red Hat OpenShift 1.2.2 RedHat registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9:sha256:9eaa6e27e421b0145987fabdc3d32bdb43a3a713d60fadda3afbcac6c1d024b4 *
Builds for Red Hat OpenShift 1.2.2 RedHat registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9:sha256:50c3023904b997bed49adcc61ca74a44a0c602e7c19e500364b70f06df341bca *
Builds for Red Hat OpenShift 1.2.2 RedHat registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9:sha256:7d9ff37487905aacab7288df7b9fddbe71f1c1d77d512b2cc4f87b5b4ff86420 *
Builds for Red Hat OpenShift 1.2.2 RedHat registry.redhat.io/openshift-builds/openshift-builds-waiters-rhel9:sha256:3f20be23175fb7dcb925d05192d6d9ba5ede56812df695c7f821c5607605b727 *
Builds for Red Hat OpenShift 1.2.2 RedHat registry.redhat.io/openshift-builds/openshift-builds-webhook-rhel9:sha256:6a9a51e13a59bd7d4be467aef8fa34ec3f5cd4f41355e50a9e1067a434ff2e0d *
Builds for Red Hat OpenShift 1.3.2 RedHat registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9:sha256:3750b75de52918c4e6b97d254123eca9133ae34a9ad18b49aa18c6e4c49e65e2 *
Builds for Red Hat OpenShift 1.3.2 RedHat registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9:sha256:63f37fd84a9aad20924b07d824b1e64170364e35dff667d395cb9c2d363e9119 *
Builds for Red Hat OpenShift 1.3.2 RedHat registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9:sha256:7533a66bce7d1618e74f28097ffe8ef758d1f1364e04993dc082829a9a4a41df *
Builds for Red Hat OpenShift 1.3.2 RedHat registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9:sha256:3c598c8e7209e5a8ee996842164d38e19020b5319837ceb7bbcbd73cf81a5585 *
Builds for Red Hat OpenShift 1.3.2 RedHat registry.redhat.io/openshift-builds/openshift-builds-waiters-rhel9:sha256:e8cfd977458e4eefc70382eb36b94f8b6e12e45860e541c013f5c2e8b4e30ada *
Builds for Red Hat OpenShift 1.3.2 RedHat registry.redhat.io/openshift-builds/openshift-builds-webhook-rhel9:sha256:b0b7abb1f28022673e75c92b6079796a6ee24130548375117eca0762d2d12f08 *
Custom Metric Autoscaler operator for Red Hat Openshift 2.15 RedHat registry.redhat.io/custom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel9:sha256:0166a9dc52e4b24030198460a061dc4fc649e6007b99213a38496aada2aaaba6 *
Custom Metric Autoscaler operator for Red Hat Openshift 2.15 RedHat registry.redhat.io/custom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel9:sha256:6e8caff3ab7ad5e103fa809f4be7a672c7ef3d9f86f26afeb9d275bdd58d73d8 *
Custom Metric Autoscaler operator for Red Hat Openshift 2.15 RedHat registry.redhat.io/custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9:sha256:e25cd6d10cc023428bfb3c82a8a59ff0620ac835a326a01ef5ea79688cbfc800 *
Red Hat OpenShift distributed tracing 3.5.1 RedHat registry.redhat.io/rhosdt/tempo-gateway-rhel8:sha256:630e24b5a39e415fbe48843ca18908634d55af2051a3f76dd538b6978f1e3669 *
Red Hat OpenShift distributed tracing 3.5.1 RedHat registry.redhat.io/rhosdt/tempo-gateway-rhel8:sha256:af8c4ae92437cb495fe07e966bbf8654bd1e4a6c3684c7462c1e158c6fecd592 *
Red Hat OpenShift distributed tracing 3.5.1 RedHat registry.redhat.io/rhosdt/opentelemetry-collector-rhel8:sha256:b7f6e9442ee2ae2b7122a9732eaa11a85b1f0264e60963819c7e5150c1457740 *
Red Hat Trusted Artifact Signer 1.1 RedHat registry.redhat.io/rhtas/createtree-rhel9:sha256:d9ff8413f1d106cb5084b48b73b205db6dd5ad82818be4111c5cb118d9d135ae *
Red Hat Trusted Artifact Signer 1.1 RedHat registry.redhat.io/rhtas/trillian-database-rhel9:sha256:7ce611aefdfedd8b2a633def482cf41f390c95b8f8c800b6163a585f117a9e2e *
Red Hat Trusted Artifact Signer 1.1 RedHat registry.redhat.io/rhtas/trillian-logserver-rhel9:sha256:76c24a38ac89ed632d38e44049f37e4997abfa27fa8cadbb8afb42575031296f *
Red Hat Trusted Artifact Signer 1.1 RedHat registry.redhat.io/rhtas/trillian-logsigner-rhel9:sha256:1f5a30a285a16635a7234c3c1763dfb385c8bffd605fc862b782bdb5c6c61ea3 *
Red Hat Trusted Artifact Signer 1.1 RedHat registry.redhat.io/rhtas/trillian-redis-rhel9:sha256:5a752cefdaf28bfc53847185cdd5fef1ee47e3dcff8472f8a8bf7bbdc224ef57 *
Red Hat Trusted Artifact Signer 1.1 RedHat registry.redhat.io/rhtas/updatetree-rhel9:sha256:8651f55805f4b32a7ca351caa642b74f88493ca3dfb52ff57cf3c2dbdbf829f7 *
Red Hat Trusted Artifact Signer 1.1 RedHat registry.redhat.io/rhtas/certificate-transparency-rhel9:sha256:dc994a95be22b0f4bab022fc362c4f44c6a7d1887a2eb0d04870d75654ec013b *
Red Hat Trusted Artifact Signer 1.1 RedHat registry.redhat.io/rhtas/timestamp-authority-rhel9:sha256:796860a3e85712c60398c36983e0ff4d45325c7a4de869da2ebf1b6ba4b19825 *
Red Hat Trusted Artifact Signer 1.1 RedHat registry.redhat.io/rhtas/rekor-backfill-redis-rhel9:sha256:6131053778ea04e437f3005f90d1138aa11ebc58e3a9295e2a8d8ef6713a52be *
Red Hat Trusted Artifact Signer 1.1 RedHat registry.redhat.io/rhtas/rekor-cli-rhel9:sha256:4bd68a4b63c15e5a09127d93a20e98508ce2ce8e4649bea3ab8e30cd83f235b2 *
Red Hat Trusted Artifact Signer 1.1 RedHat registry.redhat.io/rhtas/rekor-server-rhel9:sha256:3b8f49c41df15022f8ffdf3a8f8605b14c14f4e10eae754a06a86b6585d158b3 *
Red Hat Trusted Artifact Signer 1.1 RedHat registry.redhat.io/rhtas/cosign-rhel9:sha256:2a2aa8c1a224419be83afe46b0226e168927c19c8bd3f9c4e562e5e5caebb6a9 *
Red Hat Trusted Artifact Signer 1.1 RedHat registry.redhat.io/rhtas/gitsign-rhel9:sha256:bef55c43000f266cdb7cf6ea525f7c52f2ee532b7b487ae9752aac31ebded40f *
Golang-github-golang-jwt-jwt Ubuntu upstream *
Golang-github-golang-jwt-jwt-v5 Ubuntu upstream *

Potential Mitigations

References