Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:6084 - Security Advisory
Issued:
2023-10-24
Updated:
2023-10-24

RHSA-2023:6084 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: RHACS 3.74 enhancement and security update

Type/Severity

Security Advisory: Important

Topic

Updated images are now available for Red Hat Advanced Cluster Security. The
updated image includes new features and bug fixes.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

This release of RHACS 3.74.7 includes fixes for the following security
vulnerabilities:

  • golang: net/http, x/net/http2: rapid stream resets can cause excessive

work
(CVE-2023-39325)

  • HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS

attack
(Rapid Reset Attack) (CVE-2023-44487)

  • Various CVEs in containers for glibc security issues

A Red Hat Security Bulletin which addresses further details about this flaw
is
available in the References section.

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s)
listed in the References section.

RHACS 3.74.7 includes a new default policy called "Rapid Reset: Denial of
Service
Vulnerability in HTTP/2 Protocol". This policy alerts on deployments with
images
containing components that are susceptible to a Denial of Service (DoS)
vulnerability for HTTP/2 servers, based on CVE-2023-44487 and
CVE-2023-39325.
This policy applies to the build or deploy life cycle stage.

Solution

If you are using an earlier version of RHACS 3.74, you are advised to upgrade to patch release 3.74.7.

Affected Products

  • Red Hat Advanced Cluster Security for Kubernetes 3 x86_64
  • Red Hat Advanced Cluster Security for Kubernetes for IBM Z and LinuxONE 3 s390x
  • Red Hat Advanced Cluster Security for Kubernetes for IBM Power, little endian 3 ppc64le

Fixes

  • BZ - 2242803 - CVE-2023-44487 HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)
  • BZ - 2243296 - CVE-2023-39325 golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
  • ROX-20195 - Release RHACS 3.74.7

CVEs

  • CVE-2023-3341
  • CVE-2023-4527
  • CVE-2023-4806
  • CVE-2023-4813
  • CVE-2023-4911
  • CVE-2023-39325
  • CVE-2023-44487

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://access.redhat.com/security/vulnerabilities/RHSB-2023-003
  • https://docs.openshift.com/acs/3.74/release_notes/374-release-notes.html

ppc64le

advanced-cluster-security/rhacs-central-db-rhel8@sha256:4953938e00bf4114fa18e0520ccf20611686da2372615187e5c4f2fdfbb01e06
advanced-cluster-security/rhacs-collector-rhel8@sha256:0ae622d315c3f3b23d76b7bc864c8b3d45d53db76a1fcc46d77be0c126bb93ea
advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:8c32a894305bb7fc0ac7ed37872a8dbb09f50c387bd7eb9c955c6cd11c9cf4fe
advanced-cluster-security/rhacs-main-rhel8@sha256:0a7f042c6158dbc550e5f32ecbf5829ed925d2c9fdf30c1705ff4c3ce4bce077
advanced-cluster-security/rhacs-operator-bundle@sha256:42a9acbb0b0a6db326b51044c7e9c99f7a89b5861ac706eab1595b34146b77c4
advanced-cluster-security/rhacs-rhel8-operator@sha256:8dd2654d1e078941de8b8cbd1d9aa3348ff8893c35edb5c513116129eae74207
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:060f753e5e57904fd0b3cea1f47f5a45a300ba40c3de448dce04fc4857200127
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:83e47a2dc1741bb81aa566f2b310ef0bd47a43792bcca823cdb8ee293c3c3e82
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:7c15e7d6064a4f45e6aabb8ff309bd0244ff789ee392815d85f2321a90917929
advanced-cluster-security/rhacs-scanner-rhel8@sha256:f2ebd7e0fba97e74519ce5e05c1a5205e5a76d72ae88e8c83d4722f1f8c8950b
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:668c8f074fd4b5ee1cd55f3f4b139965b570b0344e8e3b248cc0fecc14a7e4a6

s390x

advanced-cluster-security/rhacs-central-db-rhel8@sha256:f8fa778d169160543339202f870232b6b00a1d01347f4041565cae9acc910ea9
advanced-cluster-security/rhacs-collector-rhel8@sha256:6246642e8ac76535613ae5758a0cbc1e408440de2ea2f8cc208c96d7266aac22
advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:927d84e4c8b52de401106d5aa10605eee94ce911a9d8e81e0c41d3b8beb7c63a
advanced-cluster-security/rhacs-main-rhel8@sha256:95265ddc882b2548ed35ae247b283d0f25dce30a3904717396fe17c701d4eb81
advanced-cluster-security/rhacs-operator-bundle@sha256:b8aa66884d5fdfc0383d7a6fdf34418b2c55a00f441fa41a374ca405d7b3f068
advanced-cluster-security/rhacs-rhel8-operator@sha256:2adb884147e473b17086eb7cd5462fdd4ab18e6bdc81cd81940001be4a5b67c7
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:ce71c4526b7cd5d2bebf771b38e6ac61a12c5dabe3d0f9963e27245944f9e6db
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:ad7c57277851a741e0bc2536f564e86b59be8377366f4b1b7ea79aaa662dc6fa
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:b0d4ba54ba1e9bf8afe640c9c5b2c5eed807c22423a75e39702c033e41c93229
advanced-cluster-security/rhacs-scanner-rhel8@sha256:8e8acf87581468fd98a97fe28438ea0146b3d8c2b12a322f5c63bf11b4588d81
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:358e601cd9e79a86df7bc735fc593a707ad4fc4e14ed8f39131297a26fb282c3

x86_64

advanced-cluster-security/rhacs-central-db-rhel8@sha256:c4915dcdfd96742aa5ba9ca38d0de9938ce9c85f6fffa867c35427829ee7462f
advanced-cluster-security/rhacs-collector-rhel8@sha256:623ece01f5d7af6844848879985ca0a9a50473cf3e3bb6f4923280948d9ff896
advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:e5bba2853add1a8dee9cd34a542b4baf82a50091a917c83b74ade4298528bd3e
advanced-cluster-security/rhacs-main-rhel8@sha256:729e49fb7cfe2bd21541b1e82ccbb77197285aa90486b0c1685379484a956dd9
advanced-cluster-security/rhacs-operator-bundle@sha256:55bea5ed24d5fda12c5a6ac34a908da2c471937fb2c934df1188b806ab56d96e
advanced-cluster-security/rhacs-rhel8-operator@sha256:373275fba75136a5735ce6a98b94f6b44fc6122d278fdc347f8a8c4740ebcf33
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:ad2b63ce031af12d8c31eb40652e324ea9cc5891624c4e1683c00d2948825c0f
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:b565441374903dafa3ee00f015cabdf3c16b282d143fb1c9c91dcd126697d71d
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:172711e18b4289efdda02b662beeaa6941f7b41a533410871c9505b76f6a4481
advanced-cluster-security/rhacs-scanner-rhel8@sha256:2468f097410bad3de5799b9d46801a04b4580a53d05498dcae37edf73c157826
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:2a7393086842c64287c32d7cc99ba498c53ec164b3309df59277fb1bef6bbbad

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility