RHSA-2024:0691CriticalCVSS 8.3
Red Hat Security Advisory: Errata Advisory for Red Hat OpenShift GitOps v1.9.4 security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2023-49568 — go-git: Maliciously crafted Git server replies can cause DoS on go-git clients CVE-2023-49569 — go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients CVE-2024-22424 — argo-cd: vulnerable to a cross-server request forgery (CSRF) attack
🎯 Affected products34
- Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/argo-rollouts-rhel8@sha256:34d14cedc2ecd941f1ad4d38bce019a723283d78add071ff4d36e85a10815e2a_ppc64le as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/argo-rollouts-rhel8@sha256:bf88a002fcc9d1780b9a82595181f4425f14937d9117e6f5793d41695e400ebc_arm64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/argo-rollouts-rhel8@sha256:c3d3b382770538d7388bf23a10b1915f8fc254b9f76d18751089028a0ec947ff_s390x as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/argo-rollouts-rhel8@sha256:e259d73120a0611fbabdc93b4ee9a49eee6e8fa60841a4b7398b536a34bea5a9_amd64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/argocd-rhel8@sha256:1072c8b7c1563b5b7c7eb29119ec97765c3e0dad267ad8800b8146cbe7336cc6_s390x as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/argocd-rhel8@sha256:1cca6eda59e4ed1d409aa0ef039b524e58412422cc1f492c2bc515f5905ed516_arm64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/argocd-rhel8@sha256:218da32ea9eb21533976f1d8348b46e64a878e2703e562e33e3b43a57c81a2e1_ppc64le as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/argocd-rhel8@sha256:e96c6e5d7bf4ffc828a463e4f8f48f661ca8af5487de4ecbedba1e818933aebb_amd64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/console-plugin-rhel8@sha256:4175e60402edd252b70a8762606760174aecb0463987bc307e59e0f842dc7976_amd64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/console-plugin-rhel8@sha256:6a30cc9219b91d00524216523d1c45a4123b809c03a785d4ed4e20a8efc61e35_s390x as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/console-plugin-rhel8@sha256:a39ddb1efd87a6d2032b83aa4a0afa0f51b5d125d212bc341d59242448badec5_ppc64le as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/console-plugin-rhel8@sha256:f4dbcf9637738494a0906ab3da3e2935761ad2b1194a8f5797490b01523fa875_arm64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/dex-rhel8@sha256:60b93bcaf87c4b277bbfc18a920d246363452e0f5b1156333312e5b737bbf381_amd64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/dex-rhel8@sha256:962c98496645544fba458f5862aa4bc8abf43c6c95021127c75a7f9f3a64aab0_s390x as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/dex-rhel8@sha256:c80e9ddfe27033af92d26aa16da7a2211bdca4a17d2d08adb6bb79aed39e693c_arm64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/dex-rhel8@sha256:d87f8baf652171fc9bae7818f9de36412f01bd3c0b4c32cbe6da56376d9cbb1e_ppc64le as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/gitops-operator-bundle@sha256:27efa0ab1d9c69047a924bc1dcd2b56108f5f390a6da56afb6ab7a37cb4578e2_amd64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/gitops-rhel8-operator@sha256:3da9453e99b7515c0e23ceab208c98d26c98eadd521cb6c470d8b1b5eb7057e0_amd64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/gitops-rhel8-operator@sha256:412d9d2eec7c05923183621f62da212af1d133f2945c61f07fff2e45a8a8d068_ppc64le as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/gitops-rhel8-operator@sha256:b509f44121f29f65da9302ad916df9a6a65bb2e563c64f48f58347bd146a2960_s390x as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/gitops-rhel8-operator@sha256:fbf6a44ccd0ea12d8d2e069203a5d7edcbb30e9724f781d43e3529fe0abb4798_arm64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/gitops-rhel8@sha256:0e589b8414b025e6bcbfba17590341c2143115885dcef479e8e68ac929ae3820_s390x as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/gitops-rhel8@sha256:521c08653c7792317e5872c306b4e276da0d55237b9a7fa5c7ff615def846a61_amd64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/gitops-rhel8@sha256:5a446497a5e9ea9e9ee6501e0664c22b410d8eaa8bf32c6b57e11a8a34dc534e_arm64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/gitops-rhel8@sha256:8fc8c324c3f9671dbb6102676fa11c3e5dbab5cb491ba83fbe31c203b2c87e58_ppc64le as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/kam-delivery-rhel8@sha256:66f047335f44ca1fdd69f38002bceb3d01b972c293b8bfdb768e072cda2d1283_s390x as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/kam-delivery-rhel8@sha256:6751faddc6fad904c7e9b72118fd90b9b3c818522e17f2bbd7acf99d2613f59a_arm64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/kam-delivery-rhel8@sha256:7eb085abd98c9e2ea3bea9a31dda02e852e425f743c57b829c1dea170d1840a8_ppc64le as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/kam-delivery-rhel8@sha256:dd6b5013139815f60509703f6fc414974451ad73f7c93f758a8e98bf487606b4_amd64 as a component of Red Hat OpenShift GitOps 1.9
- +4 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: In cases where a bump to the latest version of go-git is not possible, a recommendation to reduce the exposure of this threat is limiting its use to only trust-worthy Git servers.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2024:0691
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://docs.openshift.com/container-platform/latest/cicd/gitops/understanding-openshift-gitops.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258165
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2259105
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0691.json