RHSA-2024:2815HighCVSS 7.4

Red Hat Security Advisory: Errata Advisory for Red Hat OpenShift GitOps v1.11.4 security update

Published
May 10, 2024
Last Modified
August 15, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2024-29180 — webpack-dev-middleware: lack of URL validation may lead to file leak

🎯 Affected products34

  • Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/argo-rollouts-rhel8@sha256:685983400e1ada4332a0416ffe47f593fab34da51dfbd1aac7f07e84524fe22b_s390x as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/argo-rollouts-rhel8@sha256:930382e80334938d8c77c535e5902a21e739b4c85b6ec3e7594d1f974d215d68_amd64 as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/argo-rollouts-rhel8@sha256:bdd0bb4fb7deefedde48b96c1bf400c0159869ae0a18658aaf93c5bd34bcfe8b_ppc64le as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/argo-rollouts-rhel8@sha256:ea5ba2ed0a48e249b413d234a09bc0b7b82127078bbf37b6c183d31625cb6dc8_arm64 as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/argocd-rhel8@sha256:1ea709aea08afab4d98092f33b935600de1c1b175f03e399700fd5dd155494ec_s390x as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/argocd-rhel8@sha256:21afa76182bb4d58037b1709f46fa0600bcaaa14f1a98635fc0f41b06912925c_ppc64le as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/argocd-rhel8@sha256:4f6122194bee9ef5f62c1c19784dbef2acc13ad598a68c6049dfd3ce2a830089_amd64 as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/argocd-rhel8@sha256:89ed0b3af1445d4e518bdb587193300c5b4fa10807f66355ae39cfafb8e7410c_arm64 as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/console-plugin-rhel8@sha256:05bba5a2ff04847ff2c0620af26c87f4dfaac91a290dab37eb4425cfc6157923_ppc64le as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/console-plugin-rhel8@sha256:278bf0667cf12db22c857b8c7a843c5611269e18c7e98f2dacb6b98f51c9453c_s390x as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/console-plugin-rhel8@sha256:638def92b1eb97ab9ec59b0c535a651f5cb42992fca30a51d347684831ccff48_amd64 as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/console-plugin-rhel8@sha256:7d673f63ef8945f66a751b901fa1cc60d12e56961ab8c004a5fd396d7d282bf0_arm64 as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/dex-rhel8@sha256:0f7c37902ff30d274e43cfa6709a9bfeee4fe05372b0749a2c0b75830508c882_ppc64le as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/dex-rhel8@sha256:5398c9f35cf4da7f1ba2fd709f37c013c232c940793b15c6447c636adc891793_s390x as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/dex-rhel8@sha256:a537c13f6444058fad3fd903952eb1e2b61d8bd43ba3fcfd7511ad52cb6b0fbf_arm64 as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/dex-rhel8@sha256:de2e79f849a8bba66dbf66b72b5eceb8c8b92f15d511c049aec251fa6a4d222d_amd64 as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/gitops-operator-bundle@sha256:d8d9a224745f1952819cf831620d5b4ef08f905d80b33d66e4043e5b0163b06a_amd64 as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/gitops-rhel8-operator@sha256:0f1b867fc8c6194ec054ec8207222e13812d407a7fb1653090b7a27a06f6f831_s390x as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/gitops-rhel8-operator@sha256:36e65a2fdb47fa6e6352d2c4ba97d739390804acf45846d7d46e1ed39b58f9ce_arm64 as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/gitops-rhel8-operator@sha256:9720f6e2911e4c60cc39058de3abd033e0b2dabba01fd921925ac918793f4cfa_amd64 as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/gitops-rhel8-operator@sha256:e594459645c4584a6f0e479f15b109f5dff0ffa51510879638a57a90b0a41858_ppc64le as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/gitops-rhel8@sha256:388f2d08833e70aefd6e840582f7483ac0ce2eb271bc490d1a2c73f5dd5f5576_ppc64le as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/gitops-rhel8@sha256:6ed362945bd2aba3651d4bf65e859abe5a02e22fa536820f52e5e4ce7fd344ed_amd64 as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/gitops-rhel8@sha256:705424f8b1e5f6062fa659cdf5c9224263f5d5976aef522adbc907b000a7df0e_arm64 as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/gitops-rhel8@sha256:732281fd8fceec7d66da42744a4b307d4de9569c8ef8cb4804cf4522b3349aff_s390x as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/kam-delivery-rhel8@sha256:413df9e2d589a8d58ad8ad3ffeec6ad1e1adbc75f9ae9f2954d909e49d867c34_s390x as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/kam-delivery-rhel8@sha256:c279444dc5b611c1b5a5dcbcdc4912ef2accc92387618261f696bd9577af2c68_arm64 as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/kam-delivery-rhel8@sha256:e2a5884b0cdd1e9d1204e1731bf42eba7f270eebb62c5e3a18eafa7fc422a3ed_amd64 as a component of Red Hat OpenShift GitOps 1.11
  • openshift-gitops-1/kam-delivery-rhel8@sha256:fdad9093445ce4b8122dc804ff7ae9b6195cd7c5beac953e8fc4038a344ed533_ppc64le as a component of Red Hat OpenShift GitOps 1.11
  • +4 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (12)