Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:6828 - Security Advisory
Issued:
2023-11-08
Updated:
2023-11-08

RHSA-2023:6828 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: ACS 4.1 enhancement update

Type/Severity

Security Advisory: Important

Topic

Updated images are now available for Red Hat Advanced Cluster Security.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Updated images are now available for Red Hat Advanced Cluster Security.

Security Fix(es):

  • golang: net/http, x/net/http2: rapid stream resets can cause excessive work (Rapid Reset Attack) (CVE-2023-39325)

A Red Hat Security Bulletin which addresses further details about the Rapid Reset flaw is available in the References section.

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

This release of RHACS 4.1 includes updates to RHEL base images and includes the following fixes:

  • All containers have been rebuilt and now include container CVE fixes for CVE-2023-44487: Flaw in handling multiplexed streams in the HTTP/2 protocol and CVE-2023-40217: Python 3 ssl.SSLSocket vulnerability.
  • The HTTP/2 functionality in the RHACS Operator webhook has been disabled to mitigate CVE-2023-44487.

Solution

If you are using an earlier version of RHACS 4.1, you are advised to upgrade to patch release 4.1.5.

Affected Products

  • Red Hat Advanced Cluster Security for Kubernetes 4 x86_64
  • Red Hat Advanced Cluster Security for Kubernetes for IBM Z and LinuxONE 4 s390x
  • Red Hat Advanced Cluster Security for Kubernetes for IBM Power, little endian 4 ppc64le

Fixes

  • BZ - 2243296 - CVE-2023-39325 golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
  • ROX-20391 - hardening: disable http/2 webhook in ACS operator to mitigate CVE-2023-44487
  • ROX-20542 - hardening: disable http/2 in operator kube-rbac-proxy to mitigate CVE-2023-44487
  • ROX-20682 - Release RHACS 4.1.5

CVEs

  • CVE-2023-39325
  • CVE-2023-40217
  • CVE-2023-44487

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://access.redhat.com/security/vulnerabilities/RHSB-2023-003
  • https://docs.openshift.com/acs/4.1/release_notes/41-release-notes.html

ppc64le

advanced-cluster-security/rhacs-central-db-rhel8@sha256:2eb39cd2031da836b306c5f1abd54e5ef05373f36829e9cd3b24f2f2955a8135
advanced-cluster-security/rhacs-collector-rhel8@sha256:64b1287daff111b974cce3df8134cb09d5a4974a37412564dc02bf93df35a4c6
advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:f92dbf47b14e40ed15e8b1f9abae795e53682fbe7746a3f6cfd2f8c65fa8ac3c
advanced-cluster-security/rhacs-main-rhel8@sha256:165f94df366216d0684b323c872d968faa3fbb45723ddb6e35fb1e191000aa0e
advanced-cluster-security/rhacs-operator-bundle@sha256:51dc4946a777b0da34789ee31bfa64f09e2065a2b584a48539336603ae01004a
advanced-cluster-security/rhacs-rhel8-operator@sha256:186eaa4cf4b8896cfe4141925f26f406cc0156c676b159745d0205f4ed857951
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:cebe3e3c935995b9352b7e1b17f469f57917db4576d44d11d0ff4c37fe21948d
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:53e85c3769970a2bba52913b2c1ed8e784daf84b42de6317dd66cfe76d1591d1
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:ffde60ef6348be1e34a9eee0f2b56583fb80ee54c3d19c20de6748daa8d701b1
advanced-cluster-security/rhacs-scanner-rhel8@sha256:6c3a5aba527996b157f3609735381f256c68c5b24363b2385f25558975806458
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:b36d84b6fd8911dbecda16d8c8536ca0180e7ac51cc75a40882a6580d787b73f

s390x

advanced-cluster-security/rhacs-central-db-rhel8@sha256:225ef8caeff7d8e40d4ef1cec150a347091249c6116199a8b8cbbb2b657d40fb
advanced-cluster-security/rhacs-collector-rhel8@sha256:5aa8bd48817d3d52fe6d4d79cefa3c4b2a89716fcd96bac3a2c6dc11f663e470
advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:4b28c3fd75efed62f043c52a13f766c752799bf05500260ea46ba75b5d48bf7e
advanced-cluster-security/rhacs-main-rhel8@sha256:d273c4b9f0d02c2179ffbbf55e6fc260e797d1f4356dba2c536a77ed8c0b33dd
advanced-cluster-security/rhacs-operator-bundle@sha256:13565496a1f4cb80746d542fc13c9f024b811dfb7df84d2013bc79b5809622bc
advanced-cluster-security/rhacs-rhel8-operator@sha256:5adc8bbbfe0514d877f1c4ec9bb30dbf039634c9adba729623e7a4f6843a31fb
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:4eb0d285b528002f312db407dabec4dca4757d3759ac3a01ba422e607ddbc4d7
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:ed4a04c43fd03091f78f24df01631b5fb1e8ca79a51d075081d6c49038f14f82
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:36dbe96cd603b2da2f3a7fec55ea5132d704395d9ec01806306307f756bd1a13
advanced-cluster-security/rhacs-scanner-rhel8@sha256:5ca23d8f43543d454e24ec10aeb2f00847b4a4e9eb3fe3495a77e11222c21969
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:0a5861649885d7d224451a836a45a9e093b297df36e8f2f501208b33ac48511f

x86_64

advanced-cluster-security/rhacs-central-db-rhel8@sha256:7d1ba993b9e53c5826f7b41541bc057048ebab7f4f29a61a569d5c954c69d061
advanced-cluster-security/rhacs-collector-rhel8@sha256:c40c2b4aaa6e4d06e96772cf76ff1366284833e36a0872df636f549b58085f0d
advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:e36c72f1a70adc1e68c822304598992f902de116b44b1b08b50df4c9a46827fe
advanced-cluster-security/rhacs-main-rhel8@sha256:9d3e2bb44a4f866bd04efb8223d68f21b04855239d95d81b530f61c9f5e42bd1
advanced-cluster-security/rhacs-operator-bundle@sha256:aafaa944201871ec15cead3aa77bbdd1da76f972f3a241b894e2254a6ec09595
advanced-cluster-security/rhacs-rhel8-operator@sha256:b291129b5dfd95d707e4cf1007928c406de1f39020eef4e54d63b0ada33c6107
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:862ad7f71a230c22e97f618c930ce3f8cd080c75a9ebf00f8b7644f1564861a7
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:e08adbe1d71a9907658598547514c5b9c649f766faf14f6d912bfb0d97e6d434
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:edea8cd403c2fa9cd28706e806a5f6d9b78e8cdfa1c131eda6c2c4254d40c13e
advanced-cluster-security/rhacs-scanner-rhel8@sha256:5d6f36aaca6e9f98500fcadda71eb617c852bf0d4f0b6a71b66a343b3ec41985
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:68748b6a1e1d1f0e4709361d087e28a6db3018191a7cd3e9ba631ddb9578757f

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility