Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:2876 - Security Advisory
Issued:
2025-03-17
Updated:
2025-03-17

RHSA-2025:2876 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: ACS 4.7 enhancement and security update

Type/Severity

Security Advisory: Moderate

Topic

Updated images are now available for Red Hat Advanced Cluster Security for
Kubernetes (RHACS). The updated image includes new features and security and bug fixes.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

Description

This release of RHACS includes new features and security and bug fixes. If you are
using an earlier version of RHACS, you are advised to upgrade to this
release 4.7.0.

New features:

For a list of new features and information about them, see: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_security_for_kubernetes/4.7/html-single/release_notes/index#release-notes-47

Bugs fixed:

  • Before this update, reports remained in the DOWNLOAD state even after they were downloaded. This issue is now fixed.
  • Before this update, the logs repeatedly displayed the following error message:

"[Throttled] Could not determine network namespace: No such file or directory"

This issue occurred when the system reported errors when encountering zombie processes. With this update, the system now specifically recognizes zombie processes and adjusts the message level to a less strict classification. However, the system can still trigger an error if the detection of zombie processes exceeds a certain threshold, helping to identify faulty workloads.

  • Before this update, the Central logs were not rotated, which caused the log file for RHACS to grow indefinitely and eventually take up the entire node memory. This issue occurred because /var/log/stackrox was mounted by using an emptyDir volume, which does not persist across pod restarts and has no built-in log rotation.

With this update, logs are deleted and the emptyDir volume is recreated when you restart the Central pod. A log size limit has been introduced to prevent excessive memory usage and to ensure that the Central logs do not overload the node.

  • Before this update, Central might have filtered out selected storage.IndexReport messages representing the state of the RPM packages on a Red Hat Enterprise Linux CoreOS (RHCOS) node due to missing timestamps.

This caused issues in RHACS 4.6.0 and 4.6.1 when testing the technical preview feature of RHCOS node scanning with Scanner V4. With this update, the filter logic in Central has been adjusted to ensure that IndexReport messages are processed correctly over time.

  • Before to this update, the RHACS portal incorrectly validated Slack webhook URLs and blocked the Mattermost integration due to strict regex rules. With this update, the regex check has been removed to allow for more flexible URL formats.

Security vulnerabilities fixed:

  • axios: exposure of confidential data stored in cookies (CVE-2023-45857)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Solution

If you are using an earlier version of RHACS, you are advised to upgrade to this release 4.7.0.

Affected Products

  • Red Hat Advanced Cluster Security for Kubernetes 4 x86_64
  • Red Hat Advanced Cluster Security for Kubernetes for IBM Z and LinuxONE 4 s390x
  • Red Hat Advanced Cluster Security for Kubernetes for IBM Power, little endian 4 ppc64le
  • Red Hat Advanced Cluster Security for Kubernetes for ARM 4 aarch64

Fixes

  • BZ - 2248979 - CVE-2023-45857 axios: exposure of confidential data stored in cookies
  • ROX-28221 - Release RHACS 4.7.0

CVEs

  • CVE-2020-11023
  • CVE-2022-49043
  • CVE-2023-45857
  • CVE-2024-11187
  • CVE-2025-1094
  • CVE-2025-1244

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_security_for_kubernetes/4.7/html-single/release_notes/index#release-notes-47

aarch64

advanced-cluster-security/rhacs-central-db-rhel8@sha256:caa4ef8563d8899cd743fb25d855b5f2e46b3fd1fa3f432acaa0b59b9b5a2d4d
advanced-cluster-security/rhacs-collector-rhel8@sha256:27022231935bb9ffe0befaabdebac2160d3848b508e48a730985bd288ec4f567
advanced-cluster-security/rhacs-main-rhel8@sha256:ff7cb27e57f16901b836e871e59f4ecef063b97db06cde9e51f951d18ace442c
advanced-cluster-security/rhacs-operator-bundle@sha256:09b5751d9739adf5fadf6af360d61424bc5b07ab2cb88d1dac0fc1960d0a874c
advanced-cluster-security/rhacs-rhel8-operator@sha256:01d568cf91f1c0464009d241ca814d7eae1cceea2934bf71a42d981f9ea60efc
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:7b21dd9b2ccae1d531d27aef4855dc562f8f37ff08901f411004b2fb18a51883
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:027fcafda81781e67001fecd9233a123da1755810f80057d89be3ec8e3e3f8e3
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:3e54fbc40fd8a6010c970f32e8635947d49b310fd1706f65426f284168719230
advanced-cluster-security/rhacs-scanner-rhel8@sha256:5f468d43dd4c4c1ae355e7cc50e0f20ce24e07331aa12e72319ad7d55d30c411
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:2de11babc6fb765a98dad2a58fda56482aaf6185eecac2b8e2a367c76dc88302
advanced-cluster-security/rhacs-scanner-v4-db-rhel8@sha256:9fcdba085354d86837c514e264c8f615be8969efdc745600154c4aab0c4d687f
advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:2bc69605a00fb7f9a90af3ff722c22f16aba83d788a8d0707ca84f0b3093dbdd

ppc64le

advanced-cluster-security/rhacs-central-db-rhel8@sha256:f2d7a2c0349c8f83af5f273a141440d82d315fcf27f5ba91ce6bb0ed9bb4b2ab
advanced-cluster-security/rhacs-collector-rhel8@sha256:75ea5297043bfca6a9da827d71fe96a855af6bc61e259b547c2f9dae603be758
advanced-cluster-security/rhacs-main-rhel8@sha256:2ed0c3a6e7ba0eca9820d4d08684874c877cf9960191a29d5e329bbb3eaf1fcb
advanced-cluster-security/rhacs-operator-bundle@sha256:9578c678ae5edfd5a275a2c4f5e5100eb40c41c23e722e6df74b5e93830d4d70
advanced-cluster-security/rhacs-rhel8-operator@sha256:c8340d8f9209d0478fcfaac6568b9787c6e91471ededba2c1ddbe509d75b0a05
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:d0bc30e145867b4054ca3a85e2bbf25d92d65c3c15302b71e7019f31ee110e20
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:034efe638599601eb16e634da3587f052caf9ecb6e720e37196feae14c5e5e74
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:3cd28198c86d291076fb00580ba3ffc4ef28e7fccfee4f2089356cb7b6455f0a
advanced-cluster-security/rhacs-scanner-rhel8@sha256:41c35a7b6d212e23437c25bdeedc6cc4c8430cf370c6a6f4e8a909717b9f7c91
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:e96a6588fb148a3d43a9a754ff2cacc76ad277e55bebe6e0366224515e5183d0
advanced-cluster-security/rhacs-scanner-v4-db-rhel8@sha256:9405f26da9bebacb05636ce2e1518d5653c01c997758e6f440fac5c7095e8abe
advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:6ca836f8c73d5c81949de1e15e3960817d4733e37a3a9f2d59de7437c11e0665

s390x

advanced-cluster-security/rhacs-central-db-rhel8@sha256:96f1071284c5819b165d6345350e918402d0e6ca273004125e36afc12d9d938b
advanced-cluster-security/rhacs-collector-rhel8@sha256:19a2009c68f3c047593d653ae879a2ce8bbb2af23a966bb6fdad325684db1008
advanced-cluster-security/rhacs-main-rhel8@sha256:7b718725f3b0561aa66e0e3473d0ebbe973de82a8d3d30d83920135ead7168d2
advanced-cluster-security/rhacs-operator-bundle@sha256:12328277ebae26ac161f861d9971a8e777d390338ae4103cf98c6ed7ecb4b915
advanced-cluster-security/rhacs-rhel8-operator@sha256:b89ee59ee33bdb7672fdb27b1ee15bf222151fc7440482c711346e1ad026a8fb
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:86e5639c86bb43e19dfe6e0c0c7d77eaae25e1e6d4f649a760f2e2da60b0fb6a
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:3cf1f824206dd50a7c80a82d13f59f4b7aa519da0cd49a6bbe75e9edd929150d
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:808bb45b242795a20970d6d6adb9c7f822bf4f64ec2ea091072bd78ca5403a84
advanced-cluster-security/rhacs-scanner-rhel8@sha256:04b5d2ee9f59081a762449156b793a6d9ac23f9b852c6c1754256dff0640215d
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:fb33e8e7b931e7dc96f2745d0a9e610167e1a41ba06193a917b0401f7132fcdd
advanced-cluster-security/rhacs-scanner-v4-db-rhel8@sha256:2f35b81246cc9cb8f4a651e260a814dd97485119bac23af72f4982f14e46313d
advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:c4b291471b92a759104cd3ce7411e6f330b96a5f4cc58b02ac66456731ef4db6

x86_64

advanced-cluster-security/rhacs-central-db-rhel8@sha256:afc65b5cb463514d1e22d65f6206b394be05c611945765b69bca3527e427dfc4
advanced-cluster-security/rhacs-collector-rhel8@sha256:a0160b6abdc16c6a89a0de32651a8c72bb2f813f93677c9ce898c9e35cace237
advanced-cluster-security/rhacs-main-rhel8@sha256:2bb10273ac816df494ccb382db37f886f240bd042df4a43d0db2f40d3674b4a6
advanced-cluster-security/rhacs-operator-bundle@sha256:6937beffd348474d4d9b06f14fabfeb74efb69cf7bc60e6e12eb5b45b03014d5
advanced-cluster-security/rhacs-rhel8-operator@sha256:cbf95684b2ebc929086ac712c0dc1a00098c362f5cf95ffecff9c22e11dcefe3
advanced-cluster-security/rhacs-roxctl-rhel8@sha256:fbb9583f01c7df04d459afcaa54a6812fc5e831fe4eb6d49c9310b6751711984
advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:0c9d830e30929a410944faed8bd3de2a768c1be21a561664cafd19d1a40ce957
advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:9cafb9284abe0cf4ea58fdb3b1056fe7d21631a1f775cd24dea09d2562aed5b7
advanced-cluster-security/rhacs-scanner-rhel8@sha256:5af6541de59383dcf9498f7bce567d3f26b67a6449acc12de16cac58f10a4e30
advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:faceb5b7f1c62c4374444e6f6535d8533463362a368572b5a367b784888131f3
advanced-cluster-security/rhacs-scanner-v4-db-rhel8@sha256:71e0ff2140338d0936e1f683cd728b01a7be0ac391ab7a48e7a2e48bfcf31a3d
advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:9400f5cc87efcd3cd69c4c2042340f31248c7b53f28d7d5b7b7eb90a95fdefec

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility