RHSA-2023:0804HighCVSS 9.1
Red Hat Security Advisory: Red Hat OpenShift GitOps security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2021-4238 — goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be CVE-2022-3064 — go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents CVE-2023-23947 — ArgoCD: Users with any cluster secret update access may update out-of-bounds cluster secrets
🎯 Affected products8
- Red Hat OpenShift GitOps 1.5
- openshift-gitops-1/applicationset-rhel8@sha256:5869b9bb375b249851b6a24147fda4aea656e7f831ddae21236b4dc3be1fd8a9_amd64 as a component of Red Hat OpenShift GitOps 1.5
- openshift-gitops-1/argocd-rhel8@sha256:100795f5d8f6d7add9428e1b4838b67b59db14b0fae7372ab16c6871d4ddb32e_amd64 as a component of Red Hat OpenShift GitOps 1.5
- openshift-gitops-1/dex-rhel8@sha256:2dc9a23e5d386eb265c4387d7e601d06805d2af24f93882bf7eb9724fd98da66_amd64 as a component of Red Hat OpenShift GitOps 1.5
- openshift-gitops-1/gitops-operator-bundle@sha256:4760018938bf0f42306f6b38e88914e5bba0cd04722bea589978f6f7066d77af_amd64 as a component of Red Hat OpenShift GitOps 1.5
- openshift-gitops-1/gitops-rhel8-operator@sha256:e0405b30d399aaf0e37889c857acbb7535535a983ce4f93fe039a2d45d08c906_amd64 as a component of Red Hat OpenShift GitOps 1.5
- openshift-gitops-1/gitops-rhel8@sha256:dee762e15417ae9e9ea17b357de03a56f46ab1f1e246c96411e4a97f4ee5ac8c_amd64 as a component of Red Hat OpenShift GitOps 1.5
- openshift-gitops-1/kam-delivery-rhel8@sha256:3e8aefa1c162233b85e03f981e8b4d97bf6dcdd89e5e94648a3a6042f0443797_amd64 as a component of Red Hat OpenShift GitOps 1.5
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2023:0804
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2156729
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2163037
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2167819
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0804.json