The vendor explicitly identifies these products or versions as containing the fix.
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:0ba8b652771a517a5c724bc91bbca265a8e86efdd2e83b504c8fb309715a3758_s390x as a component of Red Hat Advanced Cluster Security 4.7
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:271dd3bfa99f1043d3ee885764fda7d3ba89c232025c1d3ad7fe45324f47473d_arm64 as a component of Red Hat Advanced Cluster Security 4.7
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:488e7716dc50df623f9088ee36120266d4db2637e2d2ce89810f1fdd8f2161f0_amd64 as a component of Red Hat Advanced Cluster Security 4.7
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:e3444345f04c1569ec97530ddd6b6e4ccd38a2887d500054ac93f76f54c07aa8_ppc64le as a component of Red Hat Advanced Cluster Security 4.7
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:4e13827b69f9e8be0771e36046c60ec35522b8ab6b93215687fbda51ba928afc_arm64 as a component of Red Hat Advanced Cluster Security 4.8
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:5a07faace45b9bb6cafd88113902b51b3753ffdf777eba47e91f009cfadec528_amd64 as a component of Red Hat Advanced Cluster Security 4.8
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:d32b4648796a4cb84487b87c122e881b0b44120cbc4487644de3d282e04b1696_s390x as a component of Red Hat Advanced Cluster Security 4.8
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:efd818242280438cd837dbb0d98de6e20f8b833e34e057ef58914cd58c4ecbf7_ppc64le as a component of Red Hat Advanced Cluster Security 4.8
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:59dd5e6cb07cf38e499d909e1c07969db6a750a941051a4f6f7c2fb11ec16cd4_ppc64le as a component of Red Hat Advanced Cluster Security 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:66ec9c8c40011633c6f62dfb1b0d238ac1dac8aa694c6bccc67d55bb3bb058da_arm64 as a component of Red Hat Advanced Cluster Security 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:bb30abe978ff9a89ef5f954d26a2536a40327f2d40bc58a75287eeb9a17e9cca_s390x as a component of Red Hat Advanced Cluster Security 4.9
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:d1097b8171d9bd2bc615eee808f636a23a6851ded7b9905262fadddb80fcd2f5_amd64 as a component of Red Hat Advanced Cluster Security 4.9
- Summary
- A denial of service flaw has been discovered in CivetWeb. The mg_handle_form_request function allows attackers to trigger a denial of service (DoS) condition by sending a specially crafted HTTP POST request containing a null byte in the payload. The server enters an infinite loop during form data parsing as a result. Multiple malicious requests will result in complete CPU exhaustion and render the service unresponsive to further requests.
- Remediation
- If you are using an earlier version of RHACS, you are advised to upgrade to the version of RHACS mentioned in the synopsis and release notes in order to take advantage of the enhancements, bug fixes, and/or security patches in the release.
