RHSA-2023:0802HighCVSS 9.1
Red Hat Security Advisory: Red Hat OpenShift GitOps security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2021-4238 — goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be CVE-2022-3064 — go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents CVE-2023-23947 — ArgoCD: Users with any cluster secret update access may update out-of-bounds cluster secrets
🎯 Affected products17
- Red Hat OpenShift GitOps 1.6
- openshift-gitops-1/argocd-rhel8@sha256:0c5bee99b57d4c22542b4db0bb3c0cbb8cfc2ec5aabbb558de46113595068959_ppc64le as a component of Red Hat OpenShift GitOps 1.6
- openshift-gitops-1/argocd-rhel8@sha256:58bba66450206469ebe607691b61afc2146d96d26ffedfc6f506fde172f31674_amd64 as a component of Red Hat OpenShift GitOps 1.6
- openshift-gitops-1/argocd-rhel8@sha256:77d3b63cebeb6a1ca940dd93a00ef2ccbca5d32b5e54ee2bbedba20f38146bc4_s390x as a component of Red Hat OpenShift GitOps 1.6
- openshift-gitops-1/dex-rhel8@sha256:ad6199629e6bfe375da2021a0b1e33a6777c5ec80b4cdc48d124c5ae66b41b91_ppc64le as a component of Red Hat OpenShift GitOps 1.6
- openshift-gitops-1/dex-rhel8@sha256:caba1edb4b29871bf13754624ce6fea8ce0fb206ff3deab74dfb1f69cdada3de_s390x as a component of Red Hat OpenShift GitOps 1.6
- openshift-gitops-1/dex-rhel8@sha256:f3eac8e34b1f47a4abed5942381ee7fab322fd448a7a38137b304424b6c14673_amd64 as a component of Red Hat OpenShift GitOps 1.6
- openshift-gitops-1/gitops-operator-bundle@sha256:eda1bdaea4ba06884aec368634a61bbb09d87403ac43fab39c4d9d1d89c5e688_amd64 as a component of Red Hat OpenShift GitOps 1.6
- openshift-gitops-1/gitops-rhel8-operator@sha256:1341134b6a64134053ef2c4ac989669eb60642f397e0635f894f89050175c1c5_ppc64le as a component of Red Hat OpenShift GitOps 1.6
- openshift-gitops-1/gitops-rhel8-operator@sha256:4bf2edccb39f3c0bfd25f94f373e72b34b2ac290627acb57702668756d1a60bc_amd64 as a component of Red Hat OpenShift GitOps 1.6
- openshift-gitops-1/gitops-rhel8-operator@sha256:54d2fecba7960cb6b9416ca2c7cd1d208738ae0ff8701d97279573588c383bc0_s390x as a component of Red Hat OpenShift GitOps 1.6
- openshift-gitops-1/gitops-rhel8@sha256:1371f75530c27f72de038581c8b5ab0c6a2a8aef034d4ba07a15c6d22d47831c_amd64 as a component of Red Hat OpenShift GitOps 1.6
- openshift-gitops-1/gitops-rhel8@sha256:419630df6398e0a9848c15e68f6d987dfe8f95f66eefab13e590ce6609baa9bb_ppc64le as a component of Red Hat OpenShift GitOps 1.6
- openshift-gitops-1/gitops-rhel8@sha256:bb006bfbf1002c21e51b27764d6a0ed8891fb1585772511ee10977deaa90b6f5_s390x as a component of Red Hat OpenShift GitOps 1.6
- openshift-gitops-1/kam-delivery-rhel8@sha256:561af97f31088277652ca919cd345656f0e553bbe372b4a2219e653f676b5328_ppc64le as a component of Red Hat OpenShift GitOps 1.6
- openshift-gitops-1/kam-delivery-rhel8@sha256:bfdc8c3bc64cbc53cc279b8567fd200154ad02f3e2070c6511955aa53fe23a5d_s390x as a component of Red Hat OpenShift GitOps 1.6
- openshift-gitops-1/kam-delivery-rhel8@sha256:c223afae61e20a596af8565937f7ae174f1de321785ab8def1fdd24f8b6d8e1d_amd64 as a component of Red Hat OpenShift GitOps 1.6
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2023:0802
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2156729
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2163037
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2167819
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0802.json