RHSA-2024:10186: Important: ACS 4.5 enhancement update
Important: ACS 4.5 enhancement update
Other sources
This release of RHACS 4.5.5 introduces the following changes:Bug fix: Fixed an issue with redirects in curl commands leading to empty files and errors in scanning. (ROX-26929) Scanner V4 now reindexes image upon indexer updates. (ROX-23956) Security fixes: encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion(CVE-2024-34156) body-parser: Denial of Service Vulnerability in body-parser (CVE-2024-45590) dompurify: DOMPurify vulnerable to tampering by prototype pollution (CVE-2024-48910) golang: archive/zip: Incorrect handling of certain ZIP files (CVE-2024-24789) golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses (CVE-2024-24790) cross-spawn: Regular expression denial of service (CVE-2024-21538) For more details about the security issue(s), including the impact, a CVSSscore, and other related information, refer to the CVE page(s) listed in theReferences section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:10186?
RHSA-2024:10186 is classified as an important update.
How do I address the issues in RHSA-2024:10186?
To resolve the issues mentioned in RHSA-2024:10186, you should apply the latest enhancement update for Red Hat Advanced Cluster Security for Kubernetes.
Which products are affected by RHSA-2024:10186?
RHSA-2024:10186 affects multiple products including Red Hat Advanced Cluster Security for Kubernetes and its variations for IBM Z, LinuxONE, and IBM Power.
What bugs were fixed in RHSA-2024:10186?
RHSA-2024:10186 fixed an issue with redirects in curl commands that caused empty files and errors during scanning.
Is there a new version associated with RHSA-2024:10186?
Yes, RHSA-2024:10186 introduces Red Hat Advanced Cluster Security for Kubernetes version 4.5.5.