Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:7443 - Security Advisory
Issued:
2024-10-01
Updated:
2024-10-01

RHSA-2024:7443 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: RHACS 4.5 enhancement and security update

Type/Severity

Security Advisory: Moderate

Topic

Updated images are now available for Red Hat Advanced Cluster Security for Kubernetes (RHACS). The updated image includes security and bug fixes.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

Description

This release of RHACS 4.5.3 includes the security fix for the following CVE:

  • (CVE-2024-39249) Inefficient Regular Expression Complexity

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

This release of RHACS includes the following updates:

  • Fixed a broken pipe error that caused the Central UI dashboard to display incomplete data.
  • Added a new `--with-database-only` option to the `roxctl central debug download-diagnostics` command. Use it to generate diagnostic bundles for troubleshooting connection issues related to policy violations and deployments.

Solution

If you are using an earlier version of RHACS 4.5, you are advised to upgrade to this patch release 4.5.3.

Affected Products

  • Red Hat Advanced Cluster Security for Kubernetes 4 x86_64
  • Red Hat Advanced Cluster Security for Kubernetes for IBM Z and LinuxONE 4 s390x
  • Red Hat Advanced Cluster Security for Kubernetes for IBM Power, little endian 4 ppc64le

Fixes

  • BZ - 2295035 - CVE-2024-39249 nodejs-async: Regular expression denial of service while parsing function in autoinject
  • ROX-26409 - Release 4.5.3

CVEs

  • CVE-2024-4032
  • CVE-2024-6232
  • CVE-2024-6923
  • CVE-2024-30203
  • CVE-2024-30205
  • CVE-2024-39249
  • CVE-2024-39331
  • CVE-2024-45490
  • CVE-2024-45491
  • CVE-2024-45492

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://docs.openshift.com/acs/4.5/release_notes/45-release-notes.html

ppc64le

advanced-cluster-security/rhacs-central-db-rhel8@sha256:c62c8292f9bb8c43bff70b637fa755f445665018026c106bf1d015d90e6ae96b
advanced-cluster-security/rhacs-collector-rhel8@sha256:6949f71b182629c28da0e89f40141b2eb3f75cda580795a383527b685d7257fb
advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:c1a79f55a25a6ec83a279025dd85905659f1f70cc8ae806842dc6b383dba3b59
advanced-cluster-security/rhacs-main-rhel8@sha256:c2a5302f3e582fb3040dd955ca24fc1592e50aa65a5cbc88422b7e7f26c73e32
advanced-cluster-security/rhacs-operator-bundle@sha256:13b48b30a2abf9ef91f5ede1d571f2dea36fa9140f7afa3d31770c776c9a3239
advanced-cluster-security/rhacs-rhel8-operator@sha256:538c5eeb08643f27e88c7a2c4e20e45c32c1fcce23c4c9f981072800f2aefcac
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:729be600c4005de5515bdd5c8e47d16242be0f50de864de84520a21796e18d52
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:e57193441a4efae62c3ef983f23b69aa3c734b0b66d48031d6b6a17fea83647a
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:69f14260b1736ad2a7d469c4e0d61717876577daf16f4a6d4b58baa97cad5ede
advanced-cluster-security/rhacs-scanner-rhel8@sha256:75ca09f4c3bf9f5a4267a54119030eb333f0fa6ed0aef4c36d90bd2820003db4
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:0303c101184f72928ff138cddff4d6d9a1d350a0a37d33f2c4ba5e7012f51ae6
advanced-cluster-security/rhacs-scanner-v4-db-rhel8@sha256:b3996eb81230c3858044bfa7180029aedc6fa8e078f54319bd0536065b536c9a
advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:e2391fdb28bd38c2466b32a0cbba2a88092707b6c435b0659468096e0ea11b27

s390x

advanced-cluster-security/rhacs-central-db-rhel8@sha256:47f8e6d6f9dae77f8e60689e1936042ae103a5af5d0e2ef49d42e14d26f786e6
advanced-cluster-security/rhacs-collector-rhel8@sha256:b789f63ed29544e44698c35d0ccdcc50d8c400ce5a299a800df59786cfc32f23
advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:3912a19251f037b2c7f081c73a3863a9fb5cf87b7d2f446a62cd96eb418f3f2e
advanced-cluster-security/rhacs-main-rhel8@sha256:eaf61da546fe8ebc97a2a65bf01d265fd494c4f5bd0332c9997d9615e37a91ca
advanced-cluster-security/rhacs-operator-bundle@sha256:e154119bfa681132b5e39f03c35699e2247a78782d2c560251e49b40ea054629
advanced-cluster-security/rhacs-rhel8-operator@sha256:5c3062d2c4135be5091a58b524ddee91a099430a0bbe1a044c646f1ba15c8ad6
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:3028aaf6f049917c4e4319f42fd74b240a96e4813445ab4948b0b46c14ae7a07
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:4a4cae4f2dd9aafaa7d669cb3bd65d2afa2200e6e78c2c1a42710a6c6f2733d9
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:3835c005d2f275cc8c5d37a762952cb8e8e3e6e24ea081002f41efef7af9bbbc
advanced-cluster-security/rhacs-scanner-rhel8@sha256:75c33e1398027fbd651a07f23e7bc696e276c260dfe9b5505327e25a6421cfc5
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:bdb5adebc505ce41e3d7a01862efa817f785bb844d999b35a38ba7ed0f4094a3
advanced-cluster-security/rhacs-scanner-v4-db-rhel8@sha256:7a23ef214f328fc15d3283f73881f74c1f71031213b5c6d1a622a69711b5f1c3
advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:6e1a8f2fd0da4edaf7745ab28ab9bfe4f445d46a531058f514dd29938f36c3ee

x86_64

advanced-cluster-security/rhacs-central-db-rhel8@sha256:32317f7f89f3da0d2581f17b7d1e958a71d5ce7d237a5b05dc5f1b866acc3557
advanced-cluster-security/rhacs-collector-rhel8@sha256:b1248c4ae062d97a771372709b377fcfefe92adbcea304e61475387e99a7a372
advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:353df6ff8332de87ad73c5c7c17e7d02105f29a40a0c02e3121a76198b5c7b35
advanced-cluster-security/rhacs-main-rhel8@sha256:c137f8bb6e2abed955d768c2017c8927978928c04b7ed84e6b4ba7e17ded9ebe
advanced-cluster-security/rhacs-operator-bundle@sha256:8bca9a8388de978872eb2834ea7563baacf3a851e1bbaf11acd507d5acce9999
advanced-cluster-security/rhacs-rhel8-operator@sha256:3c59071106b1f6f749885ca0c6a211c2519b203d1d9a57e326a3cbdf611f5705
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:228a15ffc9125b080edb786b8ad66153193e24afbd7567e3615427e640a0686a
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:cc081af30ab994b82df75e4dc476b17c4a8291f51fd0d4719ba57ad2658fb33e
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:4563fbcd2d00a3df52ee86e9c8ea93a223c0e4bb2c49aaf970199c8496781091
advanced-cluster-security/rhacs-scanner-rhel8@sha256:d0449033954c674b6a1a4b3f1edcf62b113088ad8b900161352862c42763af7c
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:482e416be3dc10e4560083f7e6e9e5cf4a0a7cbb04ca4cdbc57b230d4bd25afa
advanced-cluster-security/rhacs-scanner-v4-db-rhel8@sha256:ddee41088b5e29141ddc8f0ead3706b3a8985dcefd6e9d9925788baee4fed800
advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:f8443192bc2424f762d0298a89fd8d96385c34a00cb0bcd373098944f2156584

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility