RHSA-2023:0803HighCVSS 9.1

Red Hat Security Advisory: Red Hat OpenShift GitOps security update

Published
February 17, 2023
Last Modified
August 6, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2021-4238 — goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be CVE-2022-3064 — go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents CVE-2023-23947 — ArgoCD: Users with any cluster secret update access may update out-of-bounds cluster secrets

🎯 Affected products20

  • Red Hat OpenShift GitOps 1.7
  • openshift-gitops-1/argocd-rhel8@sha256:1162e57874f39e1edbed8db181ec06edef1585a2f643f0121fcdd291059345d8_s390x as a component of Red Hat OpenShift GitOps 1.7
  • openshift-gitops-1/argocd-rhel8@sha256:98f30bf044386bb6343a266829e40b4fdc9bd83ad4f8139d103f939b5a527b7d_amd64 as a component of Red Hat OpenShift GitOps 1.7
  • openshift-gitops-1/argocd-rhel8@sha256:eb9a7c5dcc7ef24a113743cbae3749830be6cf9116fffd591c8e244f47a5b3c8_ppc64le as a component of Red Hat OpenShift GitOps 1.7
  • openshift-gitops-1/console-plugin-rhel8@sha256:243698a0d707846209c9fbdccfc27d856c69c7fedc986244e67e15b3753c376e_ppc64le as a component of Red Hat OpenShift GitOps 1.7
  • openshift-gitops-1/console-plugin-rhel8@sha256:91462e656b5eb2a043dd47730bdf143eceb9f92f14dff3ea88f6a622e8cdbc1b_amd64 as a component of Red Hat OpenShift GitOps 1.7
  • openshift-gitops-1/console-plugin-rhel8@sha256:d14e75f35f7379306ed5c2bdde1faedf5f2a9f2ddee9e7e287e9e4a488578997_s390x as a component of Red Hat OpenShift GitOps 1.7
  • openshift-gitops-1/dex-rhel8@sha256:599d4876fdd9154183ea550dedbd29e2f62bc54ebef39f863c4e6340caa321cc_amd64 as a component of Red Hat OpenShift GitOps 1.7
  • openshift-gitops-1/dex-rhel8@sha256:87ea07546cd74311850546c8a798d49c6d206b6bf40971981d6c9449aeb5399c_s390x as a component of Red Hat OpenShift GitOps 1.7
  • openshift-gitops-1/dex-rhel8@sha256:c113d9688c45115124e4b54e670ac23309214a8bbc7be45dd247e01144bada1b_ppc64le as a component of Red Hat OpenShift GitOps 1.7
  • openshift-gitops-1/gitops-operator-bundle@sha256:ec0dba75d110318fe1513346982468591412b61e40e9dd8c9436f586977f0225_amd64 as a component of Red Hat OpenShift GitOps 1.7
  • openshift-gitops-1/gitops-rhel8-operator@sha256:b5cb00fc43571269aad5ecf0a778ec139a86ee5dcea0f9ab0f9aa8359a8cd544_s390x as a component of Red Hat OpenShift GitOps 1.7
  • openshift-gitops-1/gitops-rhel8-operator@sha256:bbf970d916e70f6c355a0f46d5aebac7a40bb7a8d0f3c88e54b4c9594a148609_ppc64le as a component of Red Hat OpenShift GitOps 1.7
  • openshift-gitops-1/gitops-rhel8-operator@sha256:e1ad747e6897f848bb678149f793381ba939580b6ea3d3e402862730e0167bbf_amd64 as a component of Red Hat OpenShift GitOps 1.7
  • openshift-gitops-1/gitops-rhel8@sha256:1bad76a860f3797db87162a6f5ecb62779211dff9aaefdce00cf18cff1eec04f_amd64 as a component of Red Hat OpenShift GitOps 1.7
  • openshift-gitops-1/gitops-rhel8@sha256:7847ed11dda4ee9dda0cc5acf4e1a2d53daee2f7eb1eeceed107d9f5f0eafdeb_ppc64le as a component of Red Hat OpenShift GitOps 1.7
  • openshift-gitops-1/gitops-rhel8@sha256:e8d07649283ee58baee5787fb91be7306a4647ceafda8e29e34c164910af5de0_s390x as a component of Red Hat OpenShift GitOps 1.7
  • openshift-gitops-1/kam-delivery-rhel8@sha256:0512e79564b78645f9f5c9eefb81c2c22f13a1b320dbd4eb5eb25f6c66096b25_s390x as a component of Red Hat OpenShift GitOps 1.7
  • openshift-gitops-1/kam-delivery-rhel8@sha256:6239f8b5efd6839cd1dfc8f032b005cc5cefcb7a94dba9508d749cbbe7306e30_amd64 as a component of Red Hat OpenShift GitOps 1.7
  • openshift-gitops-1/kam-delivery-rhel8@sha256:6cb64efe25cd6c41abe9a58176ec103a9801a8e72594396988865995cef01279_ppc64le as a component of Red Hat OpenShift GitOps 1.7

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (6)