VDB
RHSA-2025%3A1866
RHSA-2025%3A1866
PUBLISHED
CVSS 5.300000190734863 MEDIUM
There's a flaw in the PostCSS package where it fails to properly validate the input CSS, causing commented lines to be interpreted as code. An attacker may leverage that by crafting a CSS file with comments containing CSS code in order to force PostCSS to include the malicious CSS elements in its output. An successful attack may lead to integrity impact as it may inject elements in a web page when parsing untrusted CSS input.
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | odf4/mcg-core-rhel9@sha256:9435512b7d2a884db40f3db43d920bd97ca30ed13e40d9edde5c795575af284a_arm64 as a component of RHODF 4.14 for RHEL 9 | odf4/mcg-core-rhel9@sha256:9435512b7d2a884db40f3db43d920bd97ca30ed13e40d9edde5c795575af284a_arm64 |
| Red Hat | odf4/odf-multicluster-console-rhel9@sha256:4178f6964f6b59c5926159d69bb4c50ea795b3ef63c5458afc7ce003b158e935_s390x as a component of RHODF 4.14 for RHEL 9 | odf4/odf-multicluster-console-rhel9@sha256:4178f6964f6b59c5926159d69bb4c50ea795b3ef63c5458afc7ce003b158e935_s390x |
| Red Hat | odf4/mcg-cli-rhel9@sha256:5e401b1a41c2fc866705bfc5492e734423f9bf5844f00ef510131f401a2abf5d_ppc64le as a component of RHODF 4.14 for RHEL 9 | odf4/mcg-cli-rhel9@sha256:5e401b1a41c2fc866705bfc5492e734423f9bf5844f00ef510131f401a2abf5d_ppc64le |
| Red Hat | odf4/ocs-client-console-rhel9@sha256:cf04ad2b6891da8f4e246da41041543817666b18e372e7ed4cc655b3b30bf96b_s390x as a component of RHODF 4.14 for RHEL 9 | * |
| Red Hat | odf4/odf-rhel9-operator@sha256:49902142cec52e7a36e1dade3fcf09de4046859f8341866d30573022404b9e20_arm64 as a component of RHODF 4.14 for RHEL 9 | *, * |
| Red Hat | odf4/mcg-rhel9-operator@sha256:67c617a9b48c9fc683e945357d3a9bc515c6c96f782deaf573e756b42ecddf8d_amd64 as a component of RHODF 4.14 for RHEL 9 | *, * |
| Red Hat | odf4/odf-csi-addons-rhel9-operator@sha256:68d7d0e086a9389a4e112c958fc8d80cd898ad9bb45419f892805e181dbb9067_ppc64le as a component of RHODF 4.14 for RHEL 9 | *, * |
| Red Hat | odf4/odf-console-rhel9@sha256:7b6954eb8a40c21bbf96c5a3d7beb9ddf72b51bc3b4158d3d9e6cd4d78fb5340_amd64 as a component of RHODF 4.14 for RHEL 9 | *, * |
| Red Hat | odf4/ocs-client-operator-bundle@sha256:ad6314b15e7eb64b4e3a296dcc618077ec8bed1ecd068e3693781882a2d3f5b4_ppc64le as a component of RHODF 4.14 for RHEL 9 | *, * |
| Red Hat | odf4/odf-rhel9-operator@sha256:6b8f43af0d31b5c884e5550839575e71dd76fa2f8a977b692d35c62e9ae8f7d3_ppc64le as a component of RHODF 4.14 for RHEL 9 | *, * |
| Red Hat | odf4/odf-csi-addons-sidecar-rhel9@sha256:8f9faddd049d3838e3f36dc9ef0880b3fca4d5eec690fcd2e14c30e1ea0ad01b_arm64 as a component of RHODF 4.14 for RHEL 9 | * |
| Red Hat | odf4/odf-must-gather-rhel9@sha256:76455baade072661b5e22173f949b6e469b2006dbaf532101cc369c641d2b2ac_amd64 as a component of RHODF 4.14 for RHEL 9 | odf4/odf-must-gather-rhel9@sha256:76455baade072661b5e22173f949b6e469b2006dbaf532101cc369c641d2b2ac_amd64 |
| Red Hat | odf4/ocs-operator-bundle@sha256:b115bfb31941cccddfa4167901919e1b98cc24c47e8e4b4a063e3298ae674c9d_s390x as a component of RHODF 4.14 for RHEL 9 | odf4/ocs-operator-bundle@sha256:b115bfb31941cccddfa4167901919e1b98cc24c47e8e4b4a063e3298ae674c9d_s390x |
| Red Hat | odf4/odf-csi-addons-sidecar-rhel9@sha256:ef5ee8cf24e576a3236d0de809aaff3392f262c14b5d11be1afc4c7eb8457075_s390x as a component of RHODF 4.14 for RHEL 9 | *, * |
| Red Hat | odf4/odf-csi-addons-sidecar-rhel9@sha256:45a680e3d5076ad7c490fd2703f825f3519c80990af79bd922d25b8c12f8c6a8_ppc64le as a component of RHODF 4.14 for RHEL 9 | *, * |
| Red Hat | odf4/mcg-rhel9-operator@sha256:48965c2c3bc1ab26e2d541f9dbf0096d21f8611aa98ceaee12de70d54d004aa1_ppc64le as a component of RHODF 4.14 for RHEL 9 | *, * |
| Red Hat | odf4/odf-multicluster-console-rhel9@sha256:53fd29412365a97cab53ce1bf746be3e057b46b1489699e81f818e468aed2e3f_ppc64le as a component of RHODF 4.14 for RHEL 9 | * |
| Red Hat | odf4/odf-multicluster-rhel9-operator@sha256:a2c898656e50a23f3aa0b9749136dd7e24c5843be6eb6f970c04fbb5e3d7925b_amd64 as a component of RHODF 4.14 for RHEL 9 | *, * |
| Red Hat | odf4/ocs-client-console-rhel9@sha256:7d49faa18106a5e4c3c2be4fd4471e1778737dcef54d9c22cbcca33216eddc24_amd64 as a component of RHODF 4.14 for RHEL 9 | * |
| Red Hat | odf4/mcg-operator-bundle@sha256:15dff59b4e787dc97ce8d773680376d5902db0d86326182dd19f5ec5865ddc85_s390x as a component of RHODF 4.14 for RHEL 9 | *, * |
…and 159 more
Timeline
- Feb 26, 2025 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Jul 5, 2026 CVE Updated
References
- https://pkg.go.dev/vuln/GO-2024-3333 advisory
- https://access.redhat.com/errata/RHSA-2025:1866 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2294000 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2326998 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2333122 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1866.json advisory
- https://access.redhat.com/security/cve/CVE-2023-44270 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-44270 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-44270 advisory
- https://github.com/github/advisory-database/issues/2820 advisory
- https://github.com/postcss/postcss/blob/main/lib/tokenize.js#L25 advisory
- https://github.com/postcss/postcss/commit/58cc860b4c1707510c9cd1bc1fa30b423a9ad6c5 advisory
- https://github.com/postcss/postcss/releases/tag/8.4.31 advisory
- https://access.redhat.com/security/cve/CVE-2024-6104 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-6104 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-6104 advisory
- https://access.redhat.com/security/cve/CVE-2024-45338 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-45338 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45338 advisory
…and 3 more