Skip to content

ROX-28929: Patch release notes #92119

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions modules/common-attributes.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -55,9 +55,9 @@ endif::[]
:osp: Red{nbsp}Hat OpenShift
:olm-first: Operator Lifecycle Manager (OLM)
:olm: OLM
:rhacs-version: 4.5.8
:rhacs-version: 4.5.9
:ocp-supported-version: 4.11
:ocp-latest-version: 4.17
:ocp-latest-version: 4.18
:product-rosa: Red{nbsp}Hat OpenShift Service on AWS
:product-rosa-short: ROSA
:product-title: Red{nbsp}Hat Advanced Cluster Security for Kubernetes
Expand Down
23 changes: 21 additions & 2 deletions release_notes/45-release-notes.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,7 @@ toc::[]
|`4.5.6` | 11 February 2025
|`4.5.7` | 10 March 2025
|`4.5.8` | 31 March 2025
|`4.5.9` | 15 April 2025

|====

Expand Down Expand Up @@ -509,7 +510,25 @@ This release of {product-title-short} includes the following bug fix:

This release also addresses the following security vulnerabilities:

* link:https://access.redhat.com/security/cve/cve-2025-22868[CVE-2025-22868] Flaw in the `golang.org/x/oauth2/jws` package.
* link:https://access.redhat.com/security/cve/cve-2025-22869[CVE-2025-22869] Flaw in the `golang.org/x/crypto/ssh` package.
* link:https://access.redhat.com/security/cve/cve-2025-22868[CVE-2025-22868]: Flaw in the `golang.org/x/oauth2/jws` package
* link:https://access.redhat.com/security/cve/cve-2025-22869[CVE-2025-22869]: Flaw in the `golang.org/x/crypto/ssh` package

[id="about-release-459_{context}"]
== About release 4.5.9

*Release date*: 15 April 2025

This release of {product-title-short} includes the following bug fix:

* Fixed a bug to match the aggregation field of the compliance tables to the widgets for consistency.

This release also addresses the following security vulnerabilities:

* link:https://access.redhat.com/errata/RHSA-2025:2679[RHSA-2025:2679]: `libxml2` security update
* link:https://access.redhat.com/errata/RHSA-2025:1350[RHSA-2025:1350]: `libxml2` security update
* link:https://access.redhat.com/errata/RHSA-2025:1330[RSHA-2025:1330]: `openssl` security update
* link:https://access.redhat.com/security/cve/cve-2024-57083[CVE-2024-57083]: Prototype pollution in redoc can allow a DoS attack
* link:https://access.redhat.com/security/cve/cve-2024-21536[CVE-2024-21536]: Flaw in `http-proxy-middleware` package
* link:https://access.redhat.com/security/cve/cve-2025-30204[CVE-2025-30204]: Flaw in the `golang-jwt` implementation of JSON Web Tokens (JWT)

include::modules/image-versions.adoc[leveloffset=+1]