CVE-2024-12698: Red Hat Openshift Container Platform 4.18

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

An incomplete fix for ose-olm-catalogd-container was issued for the Rapid Reset Vulnerability (CVE-2023-39325/CVE-2023-44487) where only unauthenticated streams were protected, not streams created by authenticated sources.

Affected products

  • Red Hat Red Hat Openshift Container Platform 4.18: before v4.18.0-202502052031.p0.gf95a88f.assembly.stream.el9 (fixed in v4.18.0-202502052031.p0.gf95a88f.assembly.stream.el9)

Published 2024-12-18. Last modified 2026-06-17.