Red Hat Security Advisory: ACS 4.5 enhancement and security update
This release of RHACS includes fixes for the following security vulnerabilities: * npm-serialize-javascript: Cross-site Scripting (XSS) in serialize-javascript (CVE-2024-11831) * go-git: Argument injection via the URL field (CVE-2025-21613) * go-git: Go-git clients vulnerable to DoS via maliciously crafted Git server replies (CVE-2025-21614) * golang.org/x/crypto: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (CVE-2024-45337) * golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338)
AI Analysis
Technical Summary
This Red Hat security advisory covers multiple vulnerabilities fixed in RHACS 4.5 and Red Hat OpenShift Data Foundation 4.15. Key vulnerabilities include CVE-2024-11831, a Cross-site Scripting (XSS) vulnerability in the npm serialize-javascript package; CVE-2025-21613 and CVE-2025-21614, argument injection and denial of service vulnerabilities in go-git clients; CVE-2024-45337, an authorization bypass caused by misuse of ServerConfig.PublicKeyCallback in golang.org/x/crypto; and CVE-2024-45338, a non-linear parsing issue in golang.org/x/net/html. The advisory provides updated container images and software versions that address these issues. The vendor recommends upgrading to RHACS 4.5.6 and OpenShift Data Foundation 4.15.14 to apply these security fixes. No known exploits in the wild have been reported at this time.
Potential Impact
The vulnerabilities fixed in this advisory have high severity and could allow attackers to perform Cross-site Scripting (XSS), argument injection, denial of service (DoS), and authorization bypass attacks. These issues affect components used within RHACS and OpenShift Data Foundation, potentially impacting the security of Kubernetes cluster management and storage services. Exploitation could lead to unauthorized access, service disruption, or execution of malicious scripts. However, there are no known active exploits reported in the wild for these vulnerabilities as of the advisory date.
Mitigation Recommendations
Red Hat has released updated versions RHACS 4.5.6 and OpenShift Data Foundation 4.15.14 containing fixes for the listed vulnerabilities. Users should upgrade to these versions as soon as possible to mitigate the risks. The vendor advisory explicitly recommends applying these updates and does not indicate any alternative mitigations or that no action is required. Patch status is confirmed as official fixes are available.
Red Hat Security Advisory: ACS 4.5 enhancement and security update
Description
This release of RHACS includes fixes for the following security vulnerabilities: * npm-serialize-javascript: Cross-site Scripting (XSS) in serialize-javascript (CVE-2024-11831) * go-git: Argument injection via the URL field (CVE-2025-21613) * go-git: Go-git clients vulnerable to DoS via maliciously crafted Git server replies (CVE-2025-21614) * golang.org/x/crypto: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (CVE-2024-45337) * golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338)
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This Red Hat security advisory covers multiple vulnerabilities fixed in RHACS 4.5 and Red Hat OpenShift Data Foundation 4.15. Key vulnerabilities include CVE-2024-11831, a Cross-site Scripting (XSS) vulnerability in the npm serialize-javascript package; CVE-2025-21613 and CVE-2025-21614, argument injection and denial of service vulnerabilities in go-git clients; CVE-2024-45337, an authorization bypass caused by misuse of ServerConfig.PublicKeyCallback in golang.org/x/crypto; and CVE-2024-45338, a non-linear parsing issue in golang.org/x/net/html. The advisory provides updated container images and software versions that address these issues. The vendor recommends upgrading to RHACS 4.5.6 and OpenShift Data Foundation 4.15.14 to apply these security fixes. No known exploits in the wild have been reported at this time.
Potential Impact
The vulnerabilities fixed in this advisory have high severity and could allow attackers to perform Cross-site Scripting (XSS), argument injection, denial of service (DoS), and authorization bypass attacks. These issues affect components used within RHACS and OpenShift Data Foundation, potentially impacting the security of Kubernetes cluster management and storage services. Exploitation could lead to unauthorized access, service disruption, or execution of malicious scripts. However, there are no known active exploits reported in the wild for these vulnerabilities as of the advisory date.
Mitigation Recommendations
Red Hat has released updated versions RHACS 4.5.6 and OpenShift Data Foundation 4.15.14 containing fixes for the listed vulnerabilities. Users should upgrade to these versions as soon as possible to mitigate the risks. The vendor advisory explicitly recommends applying these updates and does not indicate any alternative mitigations or that no action is required. Patch status is confirmed as official fixes are available.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:8544
- Cve Count
- 12
- Additional Cves
- ["CVE-2024-21536","CVE-2024-21538","CVE-2024-29041","CVE-2024-29180","CVE-2024-37890","CVE-2024-39249","CVE-2024-45338","CVE-2024-45590","CVE-2024-48910","CVE-2025-22868","CVE-2025-30204"]
- Cvss Version
- 3.1
Threat ID: 6a160978e29bf47b50644bbb
Added to database: 05/26/2026, 20:58:32 UTC
Last enriched: 08/14/2026, 23:10:20 UTC
Last updated: 09/10/2026, 19:24:53 UTC
Views: 101
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.