RHSA-2023:3415: Important: ACS 4.0 enhancement and security update
Important: ACS 4.0 enhancement and security update
Other sources
This release of RHACS 4.0.2 includes security fixes for CVE-2023-24540, CVE-2023-24539 and CVE-2023-29400 by building RHACS with updated Golang builder. If you are using an earlier version of RHACS 4.0, you are advised to upgrade to this patch release 4.0.2.Security Issue(s) fixed: golang: html/template: improper sanitization of CSS values (CVE-2023-24539) golang: html/template: improper handling of JavaScript whitespace (CVE-2023-24540) golang: html/template: improper handling of empty HTML attributes (CVE-2023-29400) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:3415?
The severity of RHSA-2023:3415 is high with a severity value of 7.
What is the affected software for RHSA-2023:3415?
The affected software for RHSA-2023:3415 is Red Hat Advanced Cluster Security for Kubernetes.
How can I fix RHSA-2023:3415?
To fix RHSA-2023:3415, update to the latest version of Red Hat Advanced Cluster Security for Kubernetes.
Where can I find more information about RHSA-2023:3415?
You can find more information about RHSA-2023:3415 in the following references: [Bugzilla 2196026](https://bugzilla.redhat.com/show_bug.cgi?id=2196026), [Bugzilla 2196027](https://bugzilla.redhat.com/show_bug.cgi?id=2196027), [Bugzilla 2196029](https://bugzilla.redhat.com/show_bug.cgi?id=2196029).