Critical: ACS 4.3 enhancement and security update
Critical: ACS 4.6.2 enhancement and security update
A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.
Important: RHACS 3.74 enhancement and security update
Important: ACS 4.1 enhancement update
Important: ACS 4.4 enhancement and security update
Important: RHACS 4.4 enhancement and security update
Important: Red Hat Advanced Cluster Security for Kubernetes 3.73 security update
Important: ACS 4.0 enhancement and security update
Important: ACS 4.5 enhancement update
Important: ACS 4.5 enhancement and security update
Important: ACS 4.5 enhancement update
Important: ACS 4.5 enhancement and security update
Important: ACS 4.6 enhancement and security update
Important: ACS 4.7 enhancement and security update
Important: ACS 4.6 enhancement and security update
Important: RHACS 4.7 security update
Important: ACS 4.5 enhancement and security update
In Red Hat Advanced Cluster Security for Kubernetes, it was found that Notifier secrets were not properly sanitized in the GraphQL API. Authenticated ACS users could exploit this by retrieving Notifiers from the GraphQL API, revealing secrets that could then be used to escalate their privileges.
https://github.com/stackrox/stackrox/pull/1803
Important: RHACS 4.1 enhancement and security update
Important: ACS 4.2 enhancement and security update
Important: RHACS 4.0 enhancement and security update
Important: RHACS 3.74 enhancement and security update
In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user's account permissions to perform other actions.
Moderate: RHACS 4.5 enhancement and security update
Moderate: ACS 4.5 enhancement and security update
Moderate: RHACS 4.5 enhancement and security update
Moderate: ACS 4.6 enhancement and security update
Moderate: ACS 4.7 enhancement and security update
Moderate: RHACS 4.3 enhancement and security update