Lucene search

K
redhatRedHatRHSA-2023:3435
HistoryJun 05, 2023 - 9:19 a.m.

(RHSA-2023:3435) Important: Red Hat Advanced Cluster Security 3.74 for Kubernetes security update

2023-06-0509:19:59
access.redhat.com
8
red hat advanced cluster security
3.74.4
security update
kubernetes
cve-2023-24540
golang
cve-2023-24539
cve-2023-29400
cvss score
references section

0.005 Low

EPSS

Percentile

76.2%

This release of RHACS 3.74.4 includes a fix for CVE-2023-24540 by building RHACS with updated Golang.

Security Fix(es):

  • golang: html/template: improper handling of JavaScript whitespace (CVE-2023-24540)

  • golang: html/template: improper sanitization of CSS values (CVE-2023-24539)

  • golang: html/template: improper handling of empty HTML attributes (CVE-2023-29400)

For more details about the security issues, including the impact, a CVSS score, acknowledgments, and other related information, refer to the links listed in the References section.