Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:6071 - Security Advisory
Issued:
2023-10-24
Updated:
2023-10-24

RHSA-2023:6071 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: RHACS 4.0 enhancement and security update

Type/Severity

Security Advisory: Important

Topic

Updated images are now available for Red Hat Advanced Cluster Security. The updated image includes new features and bug fixes.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

This release of RHACS 4.0.5 includes fixes for the following security
vulnerabilities:

  • golang: net/http, x/net/http2: rapid stream resets can cause excessive work

(CVE-2023-39325)

  • HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack

(Rapid Reset Attack) (CVE-2023-44487)

  • Various CVEs in containers for glibc security issues

A Red Hat Security Bulletin which addresses further details about this flaw is
available in the References section.

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.

RHACS 4.0.5 includes a new default policy called "Rapid Reset: Denial of Service
Vulnerability in HTTP/2 Protocol". This policy alerts on deployments with images
containing components that are susceptible to a Denial of Service (DoS)
vulnerability for HTTP/2 servers, based on CVE-2023-44487 and CVE-2023-39325.
This policy applies to the build or deploy life cycle stage.

Solution

If you are using an earlier version of RHACS 4.0, you are advised to upgrade to patch release 4.0.5.

Affected Products

  • Red Hat Advanced Cluster Security for Kubernetes 4 x86_64
  • Red Hat Advanced Cluster Security for Kubernetes for IBM Z and LinuxONE 4 s390x
  • Red Hat Advanced Cluster Security for Kubernetes for IBM Power, little endian 4 ppc64le

Fixes

  • BZ - 2243296 - CVE-2023-39325 golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
  • ROX-20197 - Release RHACS 4.0.5

CVEs

  • CVE-2023-2602
  • CVE-2023-2603
  • CVE-2023-3341
  • CVE-2023-3899
  • CVE-2023-4527
  • CVE-2023-4806
  • CVE-2023-4813
  • CVE-2023-4911
  • CVE-2023-27536
  • CVE-2023-28321
  • CVE-2023-28484
  • CVE-2023-29469
  • CVE-2023-29491
  • CVE-2023-30630
  • CVE-2023-32681
  • CVE-2023-34969
  • CVE-2023-39325
  • CVE-2023-44487

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://docs.openshift.com/acs/4.0/release_notes/40-release-notes.html

ppc64le

advanced-cluster-security/rhacs-central-db-rhel8@sha256:a26eaebf47bcf49be38da18badf53884fe8a39b2110de2288e5f83a1ee761202
advanced-cluster-security/rhacs-collector-rhel8@sha256:a59f4e48c51878df91baf624c89a5157f7b6298a14260c0b5d6f902a2aeb574a
advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:b60c0000ee6f5c5bfcee7ecac40feac1029f8520236cec8eb76a7353f7fab2b5
advanced-cluster-security/rhacs-main-rhel8@sha256:02afc60209fa02f98325677202887cf58a04dd334ead4bea9d601b2ebca60f25
advanced-cluster-security/rhacs-operator-bundle@sha256:c2f484a894fe64522f40b9d0c16e19e933560505aec2e156f7ba543e3f0331bb
advanced-cluster-security/rhacs-rhel8-operator@sha256:b52ff18b3d963f57dc7aeb5ffc8143aaa6eb76bea5e7912fe2f0fc6e7a6f3245
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:9f2e86b59baf64ec0e15b190676a8a81d8742f4cf88e8c216bafe3fd355a534f
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:2d56340729ea34c80d7cf9342812a20ad2bb371c4ad4de656d55e3004352df1c
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:dc74190ce1f373590969a90aae941a6af820268aa41548bc06ae9c70da8afef5
advanced-cluster-security/rhacs-scanner-rhel8@sha256:e08d42e2c6c12932ec1f915bb153111076ced6d82a9205f1998e0cb970f9ca11
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:bcf867cadab62b7761bce469db61cb231fadfa4e97c141fb0d8a2946cf548f74

s390x

advanced-cluster-security/rhacs-central-db-rhel8@sha256:203f669dfecbe15bf2c026191fac9f03cc2f0a24d4e8ebaa612e03f855cd412c
advanced-cluster-security/rhacs-collector-rhel8@sha256:7b40266e9bcf63f9d17057d41a8d74a6996666a17bae8f5480d18bf68b3d36be
advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:b3f8f5122676f1a9a46f38f7cf8e265536f275ecb7c2ad08874f5e792cc12af0
advanced-cluster-security/rhacs-main-rhel8@sha256:4b727955da552e9137b8beaacb58743e242ca18c722da4c83d139d01f39ced67
advanced-cluster-security/rhacs-operator-bundle@sha256:683fc6bcd5de85b025df05e59c4ca7d895fb4a3764d65a53f5f0301fd59629a4
advanced-cluster-security/rhacs-rhel8-operator@sha256:e2c292eebafb277fbb4d273e9edfe22435b2201e08c02c04011330e0c13fa335
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:4774c909ac77d2d0efd233b54380166576ffa1695cabdc418b809e7beae4f684
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:af78c6089f148a256854511669e111271d80dc0eba571d9f47628429bce66835
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:a3829f94879b2512ae6d38f617a734e79ef9ab7de6f6c1ae1318346d6144e636
advanced-cluster-security/rhacs-scanner-rhel8@sha256:94d2ae7b3e409451320370ac05ed6a88be8546b2e756a306d904ef22a372c7b9
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:e8cf8dd749a23a9fb3ae23ed2263ada05c6e13c035535c3796eb465f9a071f8f

x86_64

advanced-cluster-security/rhacs-central-db-rhel8@sha256:ff2e32cba218f944d628ab1b12e13f47ba2f5c59198fbadfa91a48203ec65edc
advanced-cluster-security/rhacs-collector-rhel8@sha256:681c44488bef3551c8a48b955cb4f80377336474b5eff91d751df9616b403c90
advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:8d01a5d038f9f778df054ab9533ff700dfafc72a8b6e086910f2e5db0634b21b
advanced-cluster-security/rhacs-main-rhel8@sha256:39bc3203d9b1bb5031c8abdcf18b578cdb06d87939b92a1adbfe7f58f7263e5e
advanced-cluster-security/rhacs-operator-bundle@sha256:a0d9cd31d953aaf7e84f5a39f405c5aa2ea62e68d6c728a936ca1ffc4dc1b93e
advanced-cluster-security/rhacs-rhel8-operator@sha256:37d3b4a85e1214f54d485732f20a83c88a20622a66de83f5f445d9b6274cafe2
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:3062a2b35b2911df16e2c4d19bd3e231f4e4f4bd64bfb2d909e54c85eb3bb282
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:8a56051d40e5c4c82c188303b7572da6e4bf21ce1f999db97ab878f59431b8f5
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:0312f6391720d2552b067a597c6d30bd47bd72f0e173488b615b3da8e144eb0e
advanced-cluster-security/rhacs-scanner-rhel8@sha256:65a60062866c15fab1eb1af75cc0fdeeec88e7c98c8d9a428a0a8272d6246b1c
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:410b2c74ad914d4f09f1a64cd51da7ed057b891dd0f2a9803bc168f5b0a81aab

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility