RHSA-2023:0804HighCVSS 9.1

Red Hat Security Advisory: Red Hat OpenShift GitOps security update

Published
February 17, 2023
Last Modified
August 6, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2021-4238 — goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be CVE-2022-3064 — go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents CVE-2023-23947 — ArgoCD: Users with any cluster secret update access may update out-of-bounds cluster secrets

🎯 Affected products8

  • Red Hat OpenShift GitOps 1.5
  • openshift-gitops-1/applicationset-rhel8@sha256:5869b9bb375b249851b6a24147fda4aea656e7f831ddae21236b4dc3be1fd8a9_amd64 as a component of Red Hat OpenShift GitOps 1.5
  • openshift-gitops-1/argocd-rhel8@sha256:100795f5d8f6d7add9428e1b4838b67b59db14b0fae7372ab16c6871d4ddb32e_amd64 as a component of Red Hat OpenShift GitOps 1.5
  • openshift-gitops-1/dex-rhel8@sha256:2dc9a23e5d386eb265c4387d7e601d06805d2af24f93882bf7eb9724fd98da66_amd64 as a component of Red Hat OpenShift GitOps 1.5
  • openshift-gitops-1/gitops-operator-bundle@sha256:4760018938bf0f42306f6b38e88914e5bba0cd04722bea589978f6f7066d77af_amd64 as a component of Red Hat OpenShift GitOps 1.5
  • openshift-gitops-1/gitops-rhel8-operator@sha256:e0405b30d399aaf0e37889c857acbb7535535a983ce4f93fe039a2d45d08c906_amd64 as a component of Red Hat OpenShift GitOps 1.5
  • openshift-gitops-1/gitops-rhel8@sha256:dee762e15417ae9e9ea17b357de03a56f46ab1f1e246c96411e4a97f4ee5ac8c_amd64 as a component of Red Hat OpenShift GitOps 1.5
  • openshift-gitops-1/kam-delivery-rhel8@sha256:3e8aefa1c162233b85e03f981e8b4d97bf6dcdd89e5e94648a3a6042f0443797_amd64 as a component of Red Hat OpenShift GitOps 1.5

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (6)