A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.
Important: RHACS 4.7 security update
Important: ACS 4.6 enhancement and security update
Important: ACS 4.5 enhancement and security update
Important: ACS 4.5 enhancement and security update
Important: ACS 4.6 enhancement and security update
Important: ACS 4.7 enhancement and security update
Moderate: ACS 4.7 enhancement and security update
Important: ACS 4.5 enhancement update
Important: ACS 4.5 enhancement and security update
Critical: ACS 4.6.2 enhancement and security update
Moderate: ACS 4.6 enhancement and security update
Low: ACS 4.4 enhancement and security update
Important: ACS 4.5 enhancement update
Moderate: RHACS 4.5 enhancement and security update
Moderate: ACS 4.5 enhancement and security update
In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user's account permissions to perform other actions.
Moderate: RHACS 4.5 enhancement and security update
Important: RHACS 4.4 enhancement and security update
Important: ACS 4.4 enhancement and security update
Critical: ACS 4.3 enhancement and security update
Important: ACS 4.1 enhancement update
Important: RHACS 3.74 enhancement and security update
Moderate: RHACS 4.3 enhancement and security update
Important: RHACS 4.0 enhancement and security update
Important: RHACS 3.74 enhancement and security update
Important: ACS 4.2 enhancement and security update
Important: RHACS 4.1 enhancement and security update
This release of RHACS 3.74.4 includes a fix for CVE-2023-24540 by building RHACS with updated Golang.Security Fix(es): golang: html/template: improper handling of JavaScript whitespace (CVE-2023-24540) golang: html/template: improper sanitization of CSS values (CVE-2023-24539) golang: html/template: improper handling of empty HTML attributes (CVE-2023-29400) For more details about the security issues, including the impact, a CVSS score, acknowledgments, and other related information, refer to the links listed in the References section.
Important: Red Hat Advanced Cluster Security for Kubernetes 3.73 security update