RHSA-2024:7443MediumCVSS 5.3
Red Hat Security Advisory: RHACS 4.5 enhancement and security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2024-39249 — nodejs-async: Regular expression denial of service while parsing function in autoinject
🎯 Affected products40
- RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-central-db-rhel8@sha256:32317f7f89f3da0d2581f17b7d1e958a71d5ce7d237a5b05dc5f1b866acc3557_amd64 as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-central-db-rhel8@sha256:47f8e6d6f9dae77f8e60689e1936042ae103a5af5d0e2ef49d42e14d26f786e6_s390x as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-central-db-rhel8@sha256:c62c8292f9bb8c43bff70b637fa755f445665018026c106bf1d015d90e6ae96b_ppc64le as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-collector-rhel8@sha256:6949f71b182629c28da0e89f40141b2eb3f75cda580795a383527b685d7257fb_ppc64le as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-collector-rhel8@sha256:b1248c4ae062d97a771372709b377fcfefe92adbcea304e61475387e99a7a372_amd64 as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-collector-rhel8@sha256:b789f63ed29544e44698c35d0ccdcc50d8c400ce5a299a800df59786cfc32f23_s390x as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:353df6ff8332de87ad73c5c7c17e7d02105f29a40a0c02e3121a76198b5c7b35_amd64 as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:3912a19251f037b2c7f081c73a3863a9fb5cf87b7d2f446a62cd96eb418f3f2e_s390x as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:c1a79f55a25a6ec83a279025dd85905659f1f70cc8ae806842dc6b383dba3b59_ppc64le as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-main-rhel8@sha256:c137f8bb6e2abed955d768c2017c8927978928c04b7ed84e6b4ba7e17ded9ebe_amd64 as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-main-rhel8@sha256:c2a5302f3e582fb3040dd955ca24fc1592e50aa65a5cbc88422b7e7f26c73e32_ppc64le as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-main-rhel8@sha256:eaf61da546fe8ebc97a2a65bf01d265fd494c4f5bd0332c9997d9615e37a91ca_s390x as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-operator-bundle@sha256:13b48b30a2abf9ef91f5ede1d571f2dea36fa9140f7afa3d31770c776c9a3239_ppc64le as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-operator-bundle@sha256:8bca9a8388de978872eb2834ea7563baacf3a851e1bbaf11acd507d5acce9999_amd64 as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-operator-bundle@sha256:e154119bfa681132b5e39f03c35699e2247a78782d2c560251e49b40ea054629_s390x as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-rhel8-operator@sha256:3c59071106b1f6f749885ca0c6a211c2519b203d1d9a57e326a3cbdf611f5705_amd64 as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-rhel8-operator@sha256:538c5eeb08643f27e88c7a2c4e20e45c32c1fcce23c4c9f981072800f2aefcac_ppc64le as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-rhel8-operator@sha256:5c3062d2c4135be5091a58b524ddee91a099430a0bbe1a044c646f1ba15c8ad6_s390x as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-roxctl-rhel8@sha256:228a15ffc9125b080edb786b8ad66153193e24afbd7567e3615427e640a0686a_amd64 as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-roxctl-rhel8@sha256:3028aaf6f049917c4e4319f42fd74b240a96e4813445ab4948b0b46c14ae7a07_s390x as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-roxctl-rhel8@sha256:729be600c4005de5515bdd5c8e47d16242be0f50de864de84520a21796e18d52_ppc64le as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:4a4cae4f2dd9aafaa7d669cb3bd65d2afa2200e6e78c2c1a42710a6c6f2733d9_s390x as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:cc081af30ab994b82df75e4dc476b17c4a8291f51fd0d4719ba57ad2658fb33e_amd64 as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:e57193441a4efae62c3ef983f23b69aa3c734b0b66d48031d6b6a17fea83647a_ppc64le as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:3835c005d2f275cc8c5d37a762952cb8e8e3e6e24ea081002f41efef7af9bbbc_s390x as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:4563fbcd2d00a3df52ee86e9c8ea93a223c0e4bb2c49aaf970199c8496781091_amd64 as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:69f14260b1736ad2a7d469c4e0d61717876577daf16f4a6d4b58baa97cad5ede_ppc64le as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-scanner-rhel8@sha256:75c33e1398027fbd651a07f23e7bc696e276c260dfe9b5505327e25a6421cfc5_s390x as a component of RHACS 4.5 for RHEL 8
- advanced-cluster-security/rhacs-scanner-rhel8@sha256:75ca09f4c3bf9f5a4267a54119030eb333f0fa6ed0aef4c36d90bd2820003db4_ppc64le as a component of RHACS 4.5 for RHEL 8
- +10 more not shown
✅ Remediation
If you are using an earlier version of RHACS 4.5, you are advised to upgrade to this patch release 4.5.3.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2024:7443
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://docs.openshift.com/acs/4.5/release_notes/45-release-notes.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2295035
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_7443.json