RHSA-2023:3435HighCVSS 8.1

Red Hat Security Advisory: Red Hat Advanced Cluster Security 3.74 for Kubernetes security update

Published
June 5, 2023
Last Modified
September 17, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2023-24539 — golang: html/template: improper sanitization of CSS values CVE-2023-24540 — golang: html/template: improper handling of JavaScript whitespace CVE-2023-29400 — golang: html/template: improper handling of empty HTML attributes

🎯 Affected products34

  • RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-central-db-rhel8@sha256:406b6ad68369bb3ca09c80c3b44e599de4c10a509bffe680ca3c10e2573895c6_ppc64le as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-central-db-rhel8@sha256:8e3a1d8022cf6c500c63e803af3b6fb991c1fcf5ade52b54b9bab7ca2563bfb6_amd64 as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-central-db-rhel8@sha256:ccf3820919ce24a8f3e4be3c9089ed16ba3d2a90f5a95316ea852f1095cf49b6_s390x as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-collector-rhel8@sha256:361633af57c336504b24d92f79959e2bdef0151544a68deba8cf2cdc829a4953_s390x as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-collector-rhel8@sha256:793053fe5bb210e362b0c5006028348decee4219561138a02ca7b3013ecb46b0_amd64 as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-collector-rhel8@sha256:b496c3acb360ccf5e06a8772b2513b7c206eae53bea77ee1bbbfa7e5672a96e6_ppc64le as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:5bec876ca801db3fc1976eec48cae2399eb95e1731476bfc5fc46414ff8d26e7_s390x as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:64b1727d87614f899ea9246cf3a15016913500bbb5005a8817c10beb930c2831_amd64 as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:7b9815779933ede015cb3ed5f2901ad2c3b339bc2177bb9a6777e832bae86adc_ppc64le as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-main-rhel8@sha256:37a457dc9ec3b6289092bb50aee9012e39635f181f69247daffb6b43f74e36d3_amd64 as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-main-rhel8@sha256:4ba9b7c96758b66e86c6195bf3da27a3abf16937921e6a6068642ae8cfc34b0e_s390x as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-main-rhel8@sha256:dd37b25843db628d6034e829e25af295d4e68dc4ae39e9f6a1120572144781f3_ppc64le as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-operator-bundle@sha256:34d88bd8a54a78f114168776bb76377e7e17f1a50eb898c92f6b8a8168f6da29_ppc64le as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-operator-bundle@sha256:655b8969f5fb4f4e7a63e4215d7718c45cc6e471b70c0c5776a17afee6f76203_s390x as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-operator-bundle@sha256:aca9396a41f339d8968dd4db09dde380d3a9c218dedeae9d99c33e28254224ce_amd64 as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-rhel8-operator@sha256:11984f5258a5fdda664b6bf348944dfee541462ec28963763574d3b2edc5cb40_s390x as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-rhel8-operator@sha256:58a2803b918cd6eb542973729428557b3dfa4e00e098c1732cba238862324edc_ppc64le as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-rhel8-operator@sha256:7c84102c2124b70789c2b2e26f4a52d23598ec8b6557534036035055770d4051_amd64 as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-roxctl-rhel8@sha256:6a9753d5ab4218adbeade340597c15ca76f975aa88fa1a004a027885b28d5c2c_ppc64le as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-roxctl-rhel8@sha256:aaf0ce7b0a9efde2caf77cb807bac644a2eb2dee1874467a708eeae42a88e7ca_s390x as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-roxctl-rhel8@sha256:bbcfba6e087848830b0c2fd25d389dec670fae9f80ebfe24baf6b03d94aa17f8_amd64 as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:a0e4d54f82ed7ba720f6086d6080cdbc3a90e909f259700639a8e529d16fd9d1_amd64 as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:c2897f799497e4437c237c8f90f11e591296abdd36e35f5d5b44e7e3de0bab19_s390x as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:e7ab820108c23bee9c85839c651776e362d1aca05a41ce4b180ca05ae6544ce8_ppc64le as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:3345fb6cd6377732488fbf4e039685787d40f8e0bc0a0a03144edf1abbed876a_amd64 as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:40976c1d8f10969bc2835cf53bd2fd54e6502ba58f850f64c3c7f1a8324b23fb_s390x as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:65bd7e1fdfe01b4fec40204a06a71ff37edac86308354161fc78e99899026c1d_ppc64le as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-scanner-rhel8@sha256:10e30c1ae5a0f56c836f03d21d9025bfdb79db9a44636d294c72cff2b58c96a6_s390x as a component of RHACS 3.74 for RHEL 8
  • advanced-cluster-security/rhacs-scanner-rhel8@sha256:268063a9b8bd80f19966ffc4ee6cc5c60a35ea399c8788c8bdfd629bb06a0105_ppc64le as a component of RHACS 3.74 for RHEL 8
  • +4 more not shown

✅ Remediation

If you are using an earlier version of RHACS 3.74, you are advised to upgrade to patch release 3.74.4. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (7)