RHSA-2025:1334: Important: ACS 4.5 enhancement and security update
Important: ACS 4.5 enhancement and security update
Other sources
This release of RHACS includes fixes for the following security vulnerabilities: npm-serialize-javascript: Cross-site Scripting (XSS) in serialize-javascript (CVE-2024-11831) go-git: Argument injection via the URL field (CVE-2025-21613) go-git: Go-git clients vulnerable to DoS via maliciously crafted Git server replies (CVE-2025-21614) golang.org/x/crypto: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (CVE-2024-45337) golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338)
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:1334?
The severity of RHSA-2025:1334 is classified as Important.
How do I fix RHSA-2025:1334?
To fix RHSA-2025:1334, update to the latest version of Red Hat Advanced Cluster Security for Kubernetes.
What vulnerabilities are addressed in RHSA-2025:1334?
RHSA-2025:1334 addresses Cross-site Scripting (XSS) in serialize-javascript and argument injection vulnerabilities.
Is RHSA-2025:1334 applicable to all Red Hat products?
No, RHSA-2025:1334 is specifically applicable to certain versions of Red Hat Advanced Cluster Security for Kubernetes.
How can I find more information about the fixes in RHSA-2025:1334?
More information about the fixes in RHSA-2025:1334 can be found in the detailed advisory provided by Red Hat.