Red Hat Security Advisory: ACS 4.3 enhancement and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2019-25210 — helm: shows secrets with --dry-run option in clear text CVE-2023-49569 — go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients CVE-2024-26147 — helm: Missing YAML Content Leads To Panic
🎯 Affected products34
- RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-central-db-rhel8@sha256:736e3e62434ec2a5839d49b343543eaa7ccb20711e6165e0bb158c82e74b2cbc_s390x as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-central-db-rhel8@sha256:91cdf66dc5d25146583cf884a3ccebe2103f1a3796033b821079b132ee1a4079_amd64 as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-central-db-rhel8@sha256:9ef866fef476c2c3ba1288feb26efc396ccc59bf85825cffd9ce28e541115d4b_ppc64le as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-collector-rhel8@sha256:686ad91f440de57326855aa496f83deb40cbaf2095eec1a20eb1c8024a1f3879_s390x as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-collector-rhel8@sha256:a6748d3781ec5cef04928646aed6eeb6d13f9552cb0978bc513968de03d04693_amd64 as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-collector-rhel8@sha256:d83a8ed415a0af5f5e1b92bd7eba83c94418f068c87aee3a2a6c0aa2f70cdb1c_ppc64le as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:12e2005d9402116dd740f2c0bece212fc17a319862d84780d9d491cdc563e83c_s390x as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:4b2bbb4058d59241281a66bfb93f7828991c5947cc82b63812e67a2c17533824_amd64 as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:6a9d0b641d5c5583a1d0a8bc2ab6cf70210d09506640e0f3910214b0abeed016_ppc64le as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-main-rhel8@sha256:10eeb829065e404a5232a9a4d33f238556958e03b827d3c88dbb7a859d20a3d6_amd64 as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-main-rhel8@sha256:6cd8653ccb833a2175c5fb691ca1718a66b9885304cc15bbf14db789e17baffd_ppc64le as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-main-rhel8@sha256:90818fa0d83c71c7312964b559ba57637f6684d3956280e616608a3384a18df9_s390x as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-operator-bundle@sha256:355567de35493ef1122e8a60385828c98ba62272aaf60d4ab6336466418ec6c9_amd64 as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-operator-bundle@sha256:3fcd7214658eefa2ee8df68fa84468b88c6f967c2685de7b1dcf51ead3bd3384_s390x as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-operator-bundle@sha256:59317dcd8a520e3840ac191c634ec808339e7ac2779652530bbe35d5206a19d3_ppc64le as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-rhel8-operator@sha256:4068b92d696b38aaf9a5e02d7286caf3d0b850b445c83f604693e71bd8b99fc1_amd64 as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-rhel8-operator@sha256:52055750c7ebac6cc8da8094476048485f2d588b13e52bc6ae2aeda27e775276_s390x as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-rhel8-operator@sha256:cec628e76d2b083fe3bdd0633fbe9512f93879bac8415a737c5b724daf6aecdc_ppc64le as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-roxctl-rhel8@sha256:06fd6c23e567a898abe781090c28d4fb21c659ecfbc3ab7be67239295979ab62_ppc64le as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-roxctl-rhel8@sha256:7e4a97c0ad170ecffcf78809580bff38158feca5967f53272848e758aed80577_amd64 as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-roxctl-rhel8@sha256:b684f6d10a29563ba568a4a764498898d60cfe6cd3ffb0baac288bf9103b440d_s390x as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:3dba7e060bd7940b58e64ddf9d5fcfa8295161bbd9ae685f75b4a98a652f0060_amd64 as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:6f9bcb1ef6528a8fb81d8d1dfa82afbcc736a7e3d92750bf3d26aaf3fa8d7305_ppc64le as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:db4cbc0724e42f3e788a6de15af4e41ae85492bc230e01ea67b6954a08bad41c_s390x as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:01dbb08c96001b53359e40ca056250cf3a2a601885f85164a8471960284332e2_ppc64le as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:08ff0cc9c396ab7764d79c1749cbaadd09cf9f2d947f8559d9a122a54c9e7cb8_amd64 as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:3253ba914c3e0b7a2d50d2881b475bbf4b2e78800ba590fef3a0d3c9f91ec55f_s390x as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-scanner-rhel8@sha256:5b6b617e4a2af756b1e41ba198f6d89b89b38bb00fc7836ab7ac7bda16628edf_amd64 as a component of RHACS 4.3 for RHEL 8
- advanced-cluster-security/rhacs-scanner-rhel8@sha256:9e0be36291581bd67c9e0ed2f1c204cfff143b8f37bb2d83a7e2e64901f174bd_ppc64le as a component of RHACS 4.3 for RHEL 8
- +4 more not shown
✅ Remediation
If you are using an earlier version of RHACS 4.3, you are advised to upgrade to patch release 4.3.6. Workaround: In cases where a bump to the latest version of go-git is not possible, a recommendation to reduce the exposure of this threat is limiting its use to only trust-worthy Git servers. Workaround: If a malicious plugin has been added which is causing all Helm client commands to panic, the malicious plugin can be manually removed from the filesystem. If using Helm SDK versions prior to 3.14.2, calls to affected functions can use recover to catch the panic.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2024:1549
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258143
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265440
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1549.json