RHSA-2024:1570: Important: ACS 4.4 enhancement and security update
Important: ACS 4.4 enhancement and security update
Other sources
Updated images are now available for Red Hat Advanced Cluster Security. The<br>updated image includes new features and bug fixes.<br>This release includes the following features and updates:<br><li> New Compliance capabilities (Technology Preview)</li> <li> Network graph enhancements for internal entities</li> <li> Build-time network policy tools is now generally available</li> <li> Init-bundle graphical user interface improvements</li> <li> eBPF CO-RE collection method enabled by default</li> <li> Bring your own database for RHACS Central is now generally available</li> <li> Support RHACS on ROSA hosted control plane</li> <li> Life cycle updates</li> <li> Integration with Red Hat OpenShift Cluster Manager and Paladin Cloud to discover unsecured clusters</li> <li> Migration to stock Red Hat OpenShift SCCs during manual upgrade by using roxctl CLI</li> <li> Cluster discovery by using cloud source integrations</li> <li> Short-lived API tokens for Central</li> <li> Enhanced roxctl deployment check command</li> <li> Authentication of AWS and GCP integrations by using short-lived tokens (Technology Preview)</li> <li> Scanner V4 that uses upstream ClairCore (Technology Preview)</li> <li> Filter workload CVEs by using component and component source</li> For more information, including bug fix descriptions, see <a href="https://docs.openshift.com/acs/4.4/releasenotes/44-release-notes.html." target="blank">https://docs.openshift.com/acs/4.4/releasenotes/44-release-notes.html.</a> Security fixes:<br><li> golang: net/<a href="http:" target="blank">http:</a> insufficient sanitization of Host header (CVE-2023-29406)</li> <li> go-git: Maliciously crafted Git server replies can cause DoS on go-git clients (CVE-2023-49568)</li> <li> helm: Missing YAML content leads to panic (CVE-2024-26147)</li> <li> helm: Shows secrets with --dry-run option in clear text (CVE-2019-25210)</li>
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1570?
The severity of RHSA-2024:1570 is classified as important.
How do I fix RHSA-2024:1570?
To resolve RHSA-2024:1570, update to the latest available images of Red Hat Advanced Cluster Security.
What are the new features in RHSA-2024:1570?
RHSA-2024:1570 includes new compliance capabilities and various bug fixes.
Which products are affected by RHSA-2024:1570?
RHSA-2024:1570 affects Red Hat Advanced Cluster Security for Kubernetes and its variants for IBM Z, LinuxONE, and IBM Power.
Is there a need to immediately apply RHSA-2024:1570?
It is recommended to apply RHSA-2024:1570 to benefit from important security updates and enhancements.