Skip to main content
EPSS 1.1%top 36%

Red Hat Security Advisory: ACS 4.5 enhancement and security update

0
High
Published: 02/11/2025 (02/11/2025, 21:20:30 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

This release of RHACS includes fixes for the following security vulnerabilities: * npm-serialize-javascript: Cross-site Scripting (XSS) in serialize-javascript (CVE-2024-11831) * go-git: Argument injection via the URL field (CVE-2025-21613) * go-git: Go-git clients vulnerable to DoS via maliciously crafted Git server replies (CVE-2025-21614) * golang.org/x/crypto: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (CVE-2024-45337) * golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338)

Affected software

Affected versions
=6.0=4.15.14Red HatRed Hat Advanced Cluster Security for KubernetesRHACS 4.5 for RHEL 8ppc64leadvanced-cluster-security/rhacs-central-db-rhel8@sha256:d42f1ed5f7e32313c51f59b5e10d2bafba6c51c3f47a53cec92b3bfeefca9e3c_ppc64leRHACS 4.4 for RHEL 8amd64advanced-cluster-security/rhacs-central-db-rhel8@sha256:394f4fd42c292ef68abf4a9104fe668026e394c3243ebf9b184d40a4b4b0132e_amd64Red Hat OpenShift Data FoundationRHODF 4.15 for RHEL 9odf4/cephcsi-rhel9@sha256:21b8cf141ecf150fc0810a008c8e38e370ba688c3cd6f3457c3e6fc3ee52b4d6_ppc64leRed Hat OpenShift PipelinesRed Hat OpenShift Pipelines 1.19arm64registry.redhat.io/openshift-pipelines/pipelines-console-plugin-rhel9@sha256:41802fe9a757e2619392b014e573c921e38ecec28ba8c1cf19e31e3f8340606f_arm64Red Hat OpenShift Pipelines 1.17registry.redhat.io/openshift-pipelines/pipelines-console-plugin-rhel8@sha256:ca5b6198514a2b0b84cec25b2d84f5524c3f85e22c8a4f582bf58cdc13c33d33_arm64RHODF 4.14 for RHEL 9s390xodf4/cephcsi-rhel9@sha256:e741ce258ceffff394b453da219439e788a7c60277569d2145667b0f1a27cefc_s390xRed Hat OpenShift Pipelines 1.18.0registry.redhat.io/openshift-pipelines/pipelines-console-plugin-rhel9@sha256:bc7602c4523fa8c1906e6857e61957d2d73f9e62536934da97dc5000a3e5f8eb_arm64Red Hat Ceph StorageRed Hat Ceph Storage 9.0registry.redhat.io/rhceph/alloy-rhel10@sha256:9ba3f19803f74c69368128cfd4e0e43af6cbc09b21f3b5a4ba8fc0e6c71436ca_amd64Red Hat Ceph Storage 8registry.redhat.io/rhceph/grafana-rhel9@sha256:201105cf99231b1d2465578373ce963421263f6475ce5a4e5785fb2b8de75a11_amd64Red Hat OpenShift Pipelines 1.15registry.redhat.io/openshift-pipelines/pipelines-console-plugin-rhel8@sha256:3b11a142e5018e047c185199f157089d47e86f470e9ada73d0c36cd84ae2f020_arm64Red Hat OpenShift Pipelines 1.16registry.redhat.io/openshift-pipelines/pipelines-console-plugin-rhel8@sha256:15b283d200e626cc945bd5bfb71b883948e07ed70e97fd4da5dc678aae183808_arm64Red Hat OpenShift Pipelines 1.14.6registry.redhat.io/openshift-pipelines/pipelines-console-plugin-rhel8@sha256:6aac080879cebd4bdb5f8fdbe3864f99a827a8617d28fadc3937de3a70c76d4b_arm64Red Hat OpenShift Pipelines 1.18Red Hat Ceph Storage 9>=6.0.0 <6.0.2Red Hat Enterprise LinuxRed Hat Enterprise Linux AppStream (v. 9)Red Hat CodeReady Linux Builder (v. 9)aarch64Red Hat Enterprise Linux AppStream (v. 8)Red Hat Enterprise Linux CRB (v. 8)

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 23:10:20 UTC

Technical Analysis

This Red Hat security advisory covers multiple vulnerabilities fixed in RHACS 4.5 and Red Hat OpenShift Data Foundation 4.15. Key vulnerabilities include CVE-2024-11831, a Cross-site Scripting (XSS) vulnerability in the npm serialize-javascript package; CVE-2025-21613 and CVE-2025-21614, argument injection and denial of service vulnerabilities in go-git clients; CVE-2024-45337, an authorization bypass caused by misuse of ServerConfig.PublicKeyCallback in golang.org/x/crypto; and CVE-2024-45338, a non-linear parsing issue in golang.org/x/net/html. The advisory provides updated container images and software versions that address these issues. The vendor recommends upgrading to RHACS 4.5.6 and OpenShift Data Foundation 4.15.14 to apply these security fixes. No known exploits in the wild have been reported at this time.

Potential Impact

The vulnerabilities fixed in this advisory have high severity and could allow attackers to perform Cross-site Scripting (XSS), argument injection, denial of service (DoS), and authorization bypass attacks. These issues affect components used within RHACS and OpenShift Data Foundation, potentially impacting the security of Kubernetes cluster management and storage services. Exploitation could lead to unauthorized access, service disruption, or execution of malicious scripts. However, there are no known active exploits reported in the wild for these vulnerabilities as of the advisory date.

Mitigation Recommendations

Red Hat has released updated versions RHACS 4.5.6 and OpenShift Data Foundation 4.15.14 containing fixes for the listed vulnerabilities. Users should upgrade to these versions as soon as possible to mitigate the risks. The vendor advisory explicitly recommends applying these updates and does not indicate any alternative mitigations or that no action is required. Patch status is confirmed as official fixes are available.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:8544
Cve Count
12
Additional Cves
["CVE-2024-21536","CVE-2024-21538","CVE-2024-29041","CVE-2024-29180","CVE-2024-37890","CVE-2024-39249","CVE-2024-45338","CVE-2024-45590","CVE-2024-48910","CVE-2025-22868","CVE-2025-30204"]
Cvss Version
3.1

Threat ID: 6a160978e29bf47b50644bbb

Added to database: 05/26/2026, 20:58:32 UTC

Last enriched: 08/14/2026, 23:10:20 UTC

Last updated: 09/10/2026, 19:24:53 UTC

Views: 101

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2025:1334https://access.redhat.com/security/updates/classification/#important23125792331720233312223358882335901ROX-27932Canonical URLhttps://access.redhat.com/errata/RHSA-2025:85442270863229090122927772295035231117123198842322949232455023483662354195DFBUGS-1034DFBUGS-2604Canonical URLhttps://access.redhat.com/errata/RHSA-2025:1468https://docs.openshift.com/acs/4.4/release_notes/44-release-notes.htmlROX-27933Canonical URLReference 28Reference 29Reference 30Reference 31Reference 32Reference 33Reference 34Reference 35Reference 36Reference 37Reference 38Reference 39Reference 40Reference 41Reference 42Reference 43Reference 44Reference 45Reference 46Reference 47DFBUGS-2605Canonical URLhttps://access.redhat.com/security/cve/CVE-2024-47866https://access.redhat.com/security/updates/classification/https://docs.redhat.com/en/documentation/red_hat_ceph_storage/Canonical URLCanonical URL233789323379262337927Canonical URLhttps://docs.redhat.com/en/documentation/red_hat_openshift_pipelineshttps://access.redhat.com/security/cve/cve-2024-21536https://access.redhat.com/security/cve/cve-2024-11831https://access.redhat.com/security/cve/cve-2024-48949Canonical URLCanonical URLhttps://access.redhat.com/security/cve/CVE-2025-59436Canonical URLCanonical URLCanonical URLCanonical URLCanonical URL2274457233661123550732357806236283023868732387009239004223909802393479239448923972572400637240465524046692405301Canonical URLReference 88Reference 89Reference 90Reference 91Search on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses