RHEA-2023:2102MediumCVSS 7.5
Red Hat Enhancement Advisory: ACS 4.0 enhancement update
🔗 CVE IDs covered (1)
📋 Description
CVE-2022-23524 — helm: Denial of service through string value parsing
🎯 Affected products34
- RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-central-db-rhel8@sha256:017f7776493c0af283bc90360de7c585d6f637174d71ed760e8250ba3e84405f_amd64 as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-central-db-rhel8@sha256:54402051955fcf00d5b3c2788013b2b1a4c2c2cb1f8077f6b43b95680a2a13f8_s390x as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-central-db-rhel8@sha256:7a6d5a3b8ed335bf970703bb15fb63d93a5031fb86f74b3387f745fd878af144_ppc64le as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-collector-rhel8@sha256:04aabd34daf17a573cdc9c50c655dbe5bbd53e53756745d9f52b932b1ee5d2a6_amd64 as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-collector-rhel8@sha256:1b111d7dda10ed8034027e5fb371598819e5b096dc8fa1b565c59afe2f57c223_ppc64le as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-collector-rhel8@sha256:2956a383283ca83d3f1d347730f11b4b740a85130f006115fa0fe52eb6193a59_s390x as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:354f47a53973ec673605340fb1e8212eecbfd2f46e8807381a4d28521ff0f0d9_s390x as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:8eb4d64dfe105f91e63fbaeab5e6b5b12ca266852e87cd71b0dd6d0d7cd7b339_ppc64le as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:f27fe193f7b4c5cd513b9cfc37a958ba6dbb787c0c5a01820cd1194baff9bd31_amd64 as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-main-rhel8@sha256:792806ec7b7be2de26d7459c39da2f2b70fb8a5a006ff78fa20151d6296da1cc_ppc64le as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-main-rhel8@sha256:98903b986c59b6597988bb711ba4f18a80874afbc4bbf36aeefd53f6c9e49910_amd64 as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-main-rhel8@sha256:f86b53ab40ef596cbede00d12d0a62056c88e378ea37372d114327d0dd7ba4af_s390x as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-operator-bundle@sha256:0e7e55c46aa3a9926b184d031ff0adf0e4d208819a98a78aede2a7152d52bc30_amd64 as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-operator-bundle@sha256:951beae6ef95fa9f1ed677e4f8ab3c0c381057844a7fa6a1b84c8c96201d70e2_s390x as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-operator-bundle@sha256:a5aaf42f88aa7a43462dad536d2dee8b8bdce3bf6046ab6747a3b680e0d252cf_ppc64le as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-rhel8-operator@sha256:37fbc04cfccaca6f1f46f8e2667dd72d2dca19405f36f932a2cc96571d7a66be_ppc64le as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-rhel8-operator@sha256:4c0d6b8a7fb47d877472f1863bfeec03f7f36f01ddfaf7876d4d91cbcd6d9bcc_s390x as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-rhel8-operator@sha256:facc3bf545f5b43ec551434bad89a621140fea3fff040cd4553fe475fc4aa42f_amd64 as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-roxctl-rhel8@sha256:6301bec93393fc8a0e1dafcb58f65c04692d639fad6a57dfd9bbb0ec81b0b1c5_amd64 as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-roxctl-rhel8@sha256:6858e9a39a9e7ae9073e9069d6ca41d3d15c1a8a9719b13bc4524f80643147e2_s390x as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-roxctl-rhel8@sha256:87a47736ba5b3e5cec2c5a70fd4150095b677c442fbdd8a27aa70eea6594d66b_ppc64le as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:2e6c764d3859201de961fe1d8411f994d277a1d31f6f35cbc91129516749c92a_ppc64le as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:5f6b6d9f666406f77295cd04ac36afa21d9163afe5469f9df26edeec80134cda_amd64 as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:cdf28d93b255de45e09a80c9c467e396048f626db011c0176baa5462a968b667_s390x as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:3060dc48a3a24eee4eed10437df0f390e5c6e596fa7daa449d8b14d46992b21c_s390x as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:64a6370c20200ac6a8f958372479ea191acc6e29ec325a2ffed8605138ebde5d_ppc64le as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:d50ecb364e91e90a934c34d17b97b63db30c33a30a1e8ea0b8d6f5614e125e2a_amd64 as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-scanner-rhel8@sha256:4a22fb7282d5a41b3d98db37b0f29e5de5c93ddd11a2fdfb37b5554b0728e888_amd64 as a component of RHACS 4.0 for RHEL 8
- advanced-cluster-security/rhacs-scanner-rhel8@sha256:bbf8a5ee40989b4237fba7e73d3993eaff68753029261e1b103b9cbc193294f2_ppc64le as a component of RHACS 4.0 for RHEL 8
- +4 more not shown
✅ Remediation
To take advantage of the new features, bug fixes, and enhancements in RHACS 4.0, you are advised to upgrade to RHACS 4.0. Workaround: SDK users can validate strings supplied by users that won't create large arrays causing significant memory usage before passing them to the _strvals_ functions.