Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:0304 - Security Advisory
Issued:
2024-01-18
Updated:
2024-01-18

RHSA-2024:0304 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: RHACS 3.74 enhancement and security update

Type/Severity

Security Advisory: Important

Topic

Updated images are now available for Red Hat Advanced Cluster Security 3.74. The updated images includes bug and security fixes.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

This release of RHACS 3.74.8 provides the following changes:

  • The HTTP/2 functionality in the RHACS Operator webhook has been disabled

to mitigate CVE-2023-44487.

  • Fixed postgresql vulnerabilities in multiple images.

Solution

If you are using an earlier version of RHACS 3.74, you are advised to upgrade to patch release 3.74.8.

Affected Products

  • Red Hat Advanced Cluster Security for Kubernetes 3 x86_64
  • Red Hat Advanced Cluster Security for Kubernetes for IBM Z and LinuxONE 3 s390x
  • Red Hat Advanced Cluster Security for Kubernetes for IBM Power, little endian 3 ppc64le

Fixes

  • BZ - 2228111 - CVE-2023-39417 postgresql: extension script @substitutions@ within quoting allow SQL injection
  • BZ - 2247168 - CVE-2023-5868 postgresql: Memory disclosure in aggregate function calls
  • BZ - 2247169 - CVE-2023-5869 postgresql: Buffer overrun from integer overflow in array modification
  • BZ - 2247170 - CVE-2023-5870 postgresql: Role pg_signal_backend can signal certain superuser processes.
  • ROX-20391 - hardening: disable http/2 webhook in ACS operator to mitigate CVE-2023-44487
  • ROX-20542 - hardening: disable http/2 in operator kube-rbac-proxy to mitigate CVE-2023-44487
  • ROX-21190 - Release RHACS 3.74.8
  • ROX-21784 - Upgrade postgresql to remove CVE-2023-39417
  • ROX-21785 - Upgrade postgresql to remove CVE-2023-5868
  • ROX-21786 - Upgrade postgresql to remove CVE-2023-5869
  • ROX-21787 - Upgrade postgresql to remove CVE-2023-5870

CVEs

  • CVE-2007-4559
  • CVE-2020-22217
  • CVE-2022-3094
  • CVE-2022-4904
  • CVE-2022-41862
  • CVE-2022-48337
  • CVE-2022-48339
  • CVE-2022-48468
  • CVE-2023-3446
  • CVE-2023-3817
  • CVE-2023-4016
  • CVE-2023-4641
  • CVE-2023-5678
  • CVE-2023-5868
  • CVE-2023-5869
  • CVE-2023-5870
  • CVE-2023-22745
  • CVE-2023-31130
  • CVE-2023-31486
  • CVE-2023-39417

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://docs.openshift.com/acs/3.74/release_notes/374-release-notes.html

ppc64le

advanced-cluster-security/rhacs-central-db-rhel8@sha256:c6c389aed1fa429d92b38c137a9036d25e7780fcc6ae93850419b835048aaa69
advanced-cluster-security/rhacs-collector-rhel8@sha256:fe52bc3ea806398c0982ca15d594ed20085e7e1ca4041e81c933115bb79c8d15
advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:cdf3f9637070bb684a8c5f08d91ae21b068e813190db3e55638e8688410e6703
advanced-cluster-security/rhacs-main-rhel8@sha256:0da809964e0abfd857718ec4defa91a2a097649fcf25c88d593ff52092496787
advanced-cluster-security/rhacs-operator-bundle@sha256:eacae828588cd2d5bbb41ffdec56f20e8c8113a0549ff218c121826d7e9601fc
advanced-cluster-security/rhacs-rhel8-operator@sha256:4dc99f97f81df5236b37c19bca4094c54835f00303fca696442fddd0c315b290
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:4c0b2c0246fa78a2c2d52f7439b007465ef67b26bc213353df0be459c971aab2
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:3342ed9349de59d7d14a32425aadf850aef4ceeaacb5467a1e118a938e34283f
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:36c4f9404f0ee7457d5a1063b6b9b91c7e24c2c1e02a6902516afbf42adcc755
advanced-cluster-security/rhacs-scanner-rhel8@sha256:2c06eafb5cc0a09680545448948b4633712bdab454aa476cd807e92b2dfe8f3d
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:fc5fc6eac2a6746a5094df214c4e0d4d6d3849f0d616b1765cd89d676f28e198

s390x

advanced-cluster-security/rhacs-central-db-rhel8@sha256:9738b66518ede2a453399c35bbe4370a4692dd6acd2e3a29036a4074abcbfc3e
advanced-cluster-security/rhacs-collector-rhel8@sha256:f62686b1a19bd8fe0ef052bbde4b8b84c11ed1de1efabd0bd59fa7531c8a3bdb
advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:a8b18859c5f5f1f9242e3346af6bdcdf6c23580fae2b8d9bd283b935805ca7b4
advanced-cluster-security/rhacs-main-rhel8@sha256:efb1a786e49503bb7e10278cea988597d5fe8d6a19e4e106137d8eab36afb716
advanced-cluster-security/rhacs-operator-bundle@sha256:c123d584c63179723718832aba90561ed4838e6546a8c25698dbfe008807b5c7
advanced-cluster-security/rhacs-rhel8-operator@sha256:25260d6f82dc46ca17c25fe78dc7b3cba831b5b72e030f5fb1841c66f5036e02
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:b37d6a57e78698f664b072e0ffe2f8f6e438cd696cf9ba14a73ca5344690abd7
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:25388d80461f93743df2b2ea0fe6e332ee86f23d452596751cfa0948c378a995
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:ec99dd00a1ec67096d4a58389c813118f4392d4b23c3954c280919fd63281674
advanced-cluster-security/rhacs-scanner-rhel8@sha256:572dba1997ebdf2b5d509dc260208f5fadcd76cf3e1bd5ac0d4b1c31d43eecc0
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:60dedd6dd3ec34767e615cc8c33378164cac92dd651132221e38ed9b9e02bc8e

x86_64

advanced-cluster-security/rhacs-central-db-rhel8@sha256:4f8a9b5a334d2a2ddcd8d1174a007fc75722b8a1ef53db951767bfcf8a2a55cd
advanced-cluster-security/rhacs-collector-rhel8@sha256:d1908d4ad00269a2e46840f13fe28b1ebfe58010c2e6e63d2b007242673b574f
advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:36f8aee19c860cea156b1faf5795fd46bee58af9993d35e68d0a9a2dab622108
advanced-cluster-security/rhacs-main-rhel8@sha256:ecba5d7dbbf74e3a7894c7d18ebe32607c6234513f0b498119015d2ecf88f241
advanced-cluster-security/rhacs-operator-bundle@sha256:9ba3858a639c3e8e50a2445e54eea49ad4555a02de8597708bb17128b1778780
advanced-cluster-security/rhacs-rhel8-operator@sha256:96f61ccafc4dccfa78948f31fa5253ab958a069412439e59ccca59a8ef49910b
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:1694bf23fe49471992572a0dd784ecdc3095908f61d447e278c590fa80c3e7b8
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:19a8efae0c7b616f3f14b08b2d8e962e71b22a572b95aa8d99c9671296985ed2
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:f72eba20d8474e5da3ee7f54f6d5d873922bbaecf9a79d9620421dd1363627a8
advanced-cluster-security/rhacs-scanner-rhel8@sha256:aa086700ba7628b710b80abf65ae5d936830ede5c26ff90bb36cdbb7db590a48
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:6ecc71fea35832d06bc898da42e5a60536b6f75e119f5dc2789a15aa6873533f

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat X (formerly Twitter)

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility