Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:5851 - Security Advisory
Issued:
2023-10-18
Updated:
2023-10-18

RHSA-2023:5851 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: RHACS 4.1 enhancement and security update

Type/Severity

Security Advisory: Important

Topic

Updated images are now available for Red Hat Advanced Cluster Security (RHACS). The updated image includes new features and bug fixes.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

This release of RHACS 4.1.4 includes fixes for the following security vulnerabilities:

  • golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-39325)
  • HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487)
  • Various CVEs in containers for glibc security issues

A Red Hat Security Bulletin which addresses further details about this flaw is available in the References section.

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

RHACS 4.1.4 includes a new default policy called "Rapid Reset: Denial of Service Vulnerability in HTTP/2 Protocol". This policy alerts on deployments with images containing components that are susceptible to a Denial of Service (DoS) vulnerability for HTTP/2 servers, based on CVE-2023-44487 and CVE-2023-39325. This policy applies to the build or deploy life cycle stage.

Solution

If you are using an earlier version of RHACS 4.1, you are advised to upgrade to patch release 4.1.4.

Affected Products

  • Red Hat Advanced Cluster Security for Kubernetes 4 x86_64
  • Red Hat Advanced Cluster Security for Kubernetes for IBM Z and LinuxONE 4 s390x
  • Red Hat Advanced Cluster Security for Kubernetes for IBM Power, little endian 4 ppc64le

Fixes

  • BZ - 2242803 - CVE-2023-44487 HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)
  • BZ - 2243296 - CVE-2023-39325 golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
  • ROX-20196 - Release RHACS 4.1.4

CVEs

  • CVE-2023-3341
  • CVE-2023-3899
  • CVE-2023-4527
  • CVE-2023-4806
  • CVE-2023-4813
  • CVE-2023-4911
  • CVE-2023-29491
  • CVE-2023-30630
  • CVE-2023-39325
  • CVE-2023-44487

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://access.redhat.com/security/vulnerabilities/RHSB-2023-003
  • https://docs.openshift.com/acs/4.1/release_notes/41-release-notes.html

ppc64le

advanced-cluster-security/rhacs-central-db-rhel8@sha256:01bd7d0eb01bbccaedb4bd874f9d25ec1de15b6ffa7d9afa772c633c901b4d19
advanced-cluster-security/rhacs-collector-rhel8@sha256:2168e357d9d8b663595aefd49434fa7b87e3dcb5dfb1aa9cceeddf656d89436f
advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:39b9d467f3b5fc5813fc2b2a27e187b62673817d98ce496a5f35551046110ed1
advanced-cluster-security/rhacs-main-rhel8@sha256:70119ac2a99ae2b42a84f18d5dfc5a719ffd183a2c6587fd2654e17b207cbaa7
advanced-cluster-security/rhacs-operator-bundle@sha256:f996eaff3c93ae2a0589c038358da2932d85f7642289e6b5cc63e87af130e0f2
advanced-cluster-security/rhacs-rhel8-operator@sha256:564a8cbb9da8f2daab1d4163a4dfffdb2fadf87808cee3d4cc0ca210cf37801c
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:356142a0cef442132a39383a807ff74c6cad931071c45f44e1f7a794accf7ed1
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:024076d8e8f8759397d35ccf6d7e23c72e301d9ac76f9f3783802306412b6e82
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:f3c15fec3acb45f2b026820460c4be9b6d13fd2d5f10b0b7ddd8692971b2201b
advanced-cluster-security/rhacs-scanner-rhel8@sha256:8ec71419eb15e2fc5300fdc7bcab0422bd0c467d718a0a37568b80df4272a0ff
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:70114bb8763ef837426eb11929134ba804f70ccfe4f54eda180eb754c465ad63

s390x

advanced-cluster-security/rhacs-central-db-rhel8@sha256:f92672857754ee0baad0e17802ec23aa3f14e11dce65b59f60a8002a21987c75
advanced-cluster-security/rhacs-collector-rhel8@sha256:192562d3cc181ff2cc14b9bf7202dd1b09c3d25c3308154d3878834c42139b8a
advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:6de4dae7bd8e1cae0bcf98e76380f10ce23e2d7868eac7189c5be44fb370c65b
advanced-cluster-security/rhacs-main-rhel8@sha256:0165f336652e61518f87398d395766f408e372f1487026e6e06c5dd37e6cca24
advanced-cluster-security/rhacs-operator-bundle@sha256:594533fdc64148e9222d6a1bfaa2ac9c912478161035b2aadb3161e6a6c7de71
advanced-cluster-security/rhacs-rhel8-operator@sha256:62be9d1228353bb890192444a8f79aa10afa9acf57b6fbae49e6751d4355eced
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:e3088b93eaf3e6114ec3706f4a86cf9a1135a19b2b9274ccd5a47d4d530d5ead
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:16c06f7d13b140eace33c92e4de25080a369fb8cb07e8cd37dab1c77e20b98dc
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:505df709de90a7c86795312064564df6365d2150ee4536332c5896f767c7dd26
advanced-cluster-security/rhacs-scanner-rhel8@sha256:949cea90dd61fa675970dc2b6e2cbf7059a3095a8e679e6de8d30cac34ee2d51
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:ce07a0fffd33647940720096d75329a6c857e49ae9ce7fc8358ad0c33adf1a4c

x86_64

advanced-cluster-security/rhacs-central-db-rhel8@sha256:bed6dd0b095914635cc4c7492e7c7f312bc84138df4dbb63ce632835697da1eb
advanced-cluster-security/rhacs-collector-rhel8@sha256:9974f6a4a1e0a9409fc5fee5addbc58ecafda1fd34231f2ac4b2972fbdbb422b
advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:ec6d6c5af603b2ca083e7a7600680e3e121daedc43c53b4c0c760463fc5e569c
advanced-cluster-security/rhacs-main-rhel8@sha256:2d91c9e119a9c6f69f5f6b44fd54cdb89a255a1f831c14c0346291a085cf1255
advanced-cluster-security/rhacs-operator-bundle@sha256:54e95a79b10a119472b6ef0351ff878e6a384b8e3100d25e943678bb120ed322
advanced-cluster-security/rhacs-rhel8-operator@sha256:38933d28d8f623e8e421708f34a56e42cddd66b09c77b90ba7d0bab1ee10e6a6
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:ad51e30709c6b9f4350473b72eed6f0cb037f41f08c675ad7868cc70462513ae
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:6455831309117beb15181b443ca8f43c42b296798f9deaae25f5e180ef67f68e
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:784f6bd4459fe4ba58dba416fcd4ad259ad71d15afef167d3331e43063813e0c
advanced-cluster-security/rhacs-scanner-rhel8@sha256:86a79d36cdbdeccd47fd477ea503b859b068a168ec95c4a44c2784300c1dc036
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:70ea0eb9f752ea313bbfcc6248c12e9e3569df023c2a88ec07305579d8ffd1bc

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility