Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:7725 - Security Advisory
Issued:
2023-12-11
Updated:
2023-12-11

RHSA-2023:7725 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: RHACS 4.3 enhancement and security update

Type/Severity

Security Advisory: Moderate

Topic

Updated images are now available for Red Hat Advanced Cluster Security. The updated image includes bug and security fixes.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

This release of RHACS 4.3.1 provides the following bug fixes:

  • Fixed an issue where a user could not log in if a role mapped to the user did not have at least `read` access for the `Access` permission.
  • Fixed an issue with editing user-defined vulnerability reports in version 4.3 that were created in a previous version and linked to a specific report scope. When editing the report in version 4.3, the report scope reference was missing, and the system returned an error message.
  • Updated and removed golang dependencies to address reported vulnerabilities, including false positives.

It provides the following security fix(es):

  • dexidp: gaining access to applications accepting that token (CVE-2022-39222)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

If you are using an earlier version of RHACS 4.3, you are advised to upgrade to patch release 4.3.1.

Affected Products

  • Red Hat Advanced Cluster Security for Kubernetes 4 x86_64
  • Red Hat Advanced Cluster Security for Kubernetes for IBM Z and LinuxONE 4 s390x
  • Red Hat Advanced Cluster Security for Kubernetes for IBM Power, little endian 4 ppc64le

Fixes

  • BZ - 2253625 - CVE-2022-39222 dexidp: gaining access to applications accepting that token
  • ROX-20927 - Lack of "Access" permission in 4.3 prevents users from logging in
  • ROX-20941 - Edit vulnerability report
  • ROX-21106 - Release RHACS 4.3.1
  • ROX-20850 - Grype and Trivy reporting Vulnerabilities on stackrox binaries

CVEs

  • CVE-2007-4559
  • CVE-2020-22217
  • CVE-2022-3094
  • CVE-2022-39222
  • CVE-2022-41862
  • CVE-2022-48337
  • CVE-2022-48339
  • CVE-2022-48468
  • CVE-2023-4016
  • CVE-2023-4641
  • CVE-2023-22745
  • CVE-2023-31130
  • CVE-2023-31486

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://docs.openshift.com/acs/4.3/release_notes/43-release-notes.html

ppc64le

advanced-cluster-security/rhacs-central-db-rhel8@sha256:a5dbf5803835c61387dac05a01a44486a2308a0e9f9f929e88b6a9b3769f8f60
advanced-cluster-security/rhacs-collector-rhel8@sha256:6402de73857f6c04a1fd5c770cd3957331b72f696a1945af880f004524b1452b
advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:0f559bc90033644e7032cb0a929f55ad4f98177f34d2e1fed5e0d3f2988def4f
advanced-cluster-security/rhacs-main-rhel8@sha256:93d6e895f55d2f60c8bf5b10031cc9c025e86f480a7b00cf00dbb54fe4080728
advanced-cluster-security/rhacs-operator-bundle@sha256:7e704564f53831e7e01c5c8298d42270a49c0dad6327b80832cf34419da00fca
advanced-cluster-security/rhacs-rhel8-operator@sha256:0c0638f9f612b93671e798881cdc1205741db4fa08086afa0e3cf57710975586
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:7744d2530bc26d872030805b583141f2aae75d9b119efa344e025c78a4e8b3c1
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:938280e962b71270c35ad82962ad0c6559c6f6a04b21b4374e193f48bf2ff021
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:e5b08b8d62f8912ca0d8650bf15cf0c4e9e648299d3d443d39c14c46bc1282a4
advanced-cluster-security/rhacs-scanner-rhel8@sha256:f2e144a772bcf40fc2cc18615a618e534f37af5da46052a94b06ab247f4dc620
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:34b1ddac79932bef05caafa82ff9862b2b9720b07a82e43ba115281e6e837a63

s390x

advanced-cluster-security/rhacs-central-db-rhel8@sha256:2e1f7f206a43b16b9eec84a9138d054a1f8c95c9b620d05160ac32bce119e78b
advanced-cluster-security/rhacs-collector-rhel8@sha256:60aaece3ac376416a47e01d834a769609891c8198a1b95bd0bf1a773b79a7cf0
advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:72a9645719f747b8d2e6b4632f0afa257d14ba1a582df1ccd989d52f98a1dcca
advanced-cluster-security/rhacs-main-rhel8@sha256:5ecf3c2aca847d8df0830ab698fe0e4b1a0216f04495d7e3b6a03440c5359d5a
advanced-cluster-security/rhacs-operator-bundle@sha256:3a37d9f7751f0ec55eed03df0acd851c0a0c83249aee98850293b94f8dd2eb04
advanced-cluster-security/rhacs-rhel8-operator@sha256:9869d3e2b2d08232aab2f3af99467758b4b95e7d4f72fed9ac6bdd29eb7da81d
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:63817765b309bccdaf47a4ed3ee0cd3c00f831e11605616da0e177e4090b1604
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:70e7614d3325f6585924b90560f4683bbe35399269509e56aa4f3e9eedf14797
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:9048d490f3da588e6c674c5e4e3f164aaee6729ba6cd11ef9427719593bb0b93
advanced-cluster-security/rhacs-scanner-rhel8@sha256:df6a5a8e9a7a0f412178ef9afd9d0788fde0023e21beb134dc2b5675a9b11a35
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:692b9eafa5bbcea2033197c0537dfbbf21bbcd2a75f3b311912193405ba4671d

x86_64

advanced-cluster-security/rhacs-central-db-rhel8@sha256:dfd07bd22ae9ff4a14b06009262650b4eedca84551aa02e0c4ae5e14460c2ed5
advanced-cluster-security/rhacs-collector-rhel8@sha256:de915faffadfd07bb41e612742380d86138049bd5cc5d51e8d2d81ec5751b29f
advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:e2d5f872de74369adde8211f2e002882c2a23e37e817b182fb0721a92a8b3d68
advanced-cluster-security/rhacs-main-rhel8@sha256:d25ed99610b530ed8c0b6ba937a6c0822e72ae61022f57c26f0cc775fabf6a21
advanced-cluster-security/rhacs-operator-bundle@sha256:90bdfd8fba74a36a81c52c2fe7abbd79158d1482699bda52af7e2caf0803b3fc
advanced-cluster-security/rhacs-rhel8-operator@sha256:acf7dabe654ffee7d6e944f810e6ab19d62ae21e5a96499d1b3898cc56d5da91
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:788627d59ebeaa64b341f704f8f493a0420c0c681b15ffcd419adf993033dd6c
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:e8643e1dcf18e4ecda5cf917d5de840e466e19a300aa4c3a2d766d5252bb76b4
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:b2f0e4561b9f960675b812fd0721d890e8feb55dbbc9eff7a1fc8cd90c27fd03
advanced-cluster-security/rhacs-scanner-rhel8@sha256:9d7f729111a93515a15ddad0f4bc69e857d25af89025847551436639e54c011f
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:c5335e389d459d6de8db7fb1fae9aff32ab1efe754751d6a1bd5d81589c146db

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility