RHSA-2024:2817HighCVSS 7.4
Red Hat Security Advisory: Errata Advisory for Red Hat OpenShift GitOps v1.10.5 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2024-29180 — webpack-dev-middleware: lack of URL validation may lead to file leak
🎯 Affected products34
- Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/argo-rollouts-rhel8@sha256:141bc9dec57c4c07ba209755e1b43fb99e2afc195f3430842b275b4c4dfcc5f5_s390x as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/argo-rollouts-rhel8@sha256:167a4ec509a83696d014c258d640956c733038ae4a711824e4fdd8b004ba7964_amd64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/argo-rollouts-rhel8@sha256:53a9bf3139c8915efcf58e72193b652923167d38df5a61d5d5fbafb61b3fab0e_ppc64le as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/argo-rollouts-rhel8@sha256:db225a8e1d83c11bad04f0aae82cd07013cc8902b5af0394d8be8bca1242ae25_arm64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/argocd-rhel8@sha256:6b85a3fc1e590ab008fdb2db4647c3eccf4540eb452c64b4ebd6a61647cbc5b8_s390x as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/argocd-rhel8@sha256:91476c66096af76505cfc23d46fbcf2478a7417f86d0dedd59e7091088bcf9ef_ppc64le as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/argocd-rhel8@sha256:babc6209cd7b170a073cb38d172de4830f8fef038fef17e10044eb41f02cbaa2_amd64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/argocd-rhel8@sha256:d4584964c9659370dac81298abb68f7b5c1eef49ad1a18c7996cd6cdac16926e_arm64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/console-plugin-rhel8@sha256:b8a1bb95b79659d5ff896734be4f28bc64c2d61560c473a4a0f1c14b1e18efe5_ppc64le as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/console-plugin-rhel8@sha256:ba13922849da5fcd6a790bee2a8a39270b56ef399d2abbb7663eb698b15993c6_amd64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/console-plugin-rhel8@sha256:cf1e480c838479f8137537ab68ae818d219c40e58008a03214b0e5b6a3046730_arm64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/console-plugin-rhel8@sha256:f01f628665e7a1d3ecca7fe2f86a461fe100d8892c1e6ad848cc63c793585d0f_s390x as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/dex-rhel8@sha256:416353d665f078404aeb21c19099f342157e01eab321e50ff052565e036f9b0e_amd64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/dex-rhel8@sha256:c3fcaa38e7883f3573628c1d99bd1cdd0fcb19061371009ab118902269bbf7b3_ppc64le as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/dex-rhel8@sha256:fce845415ec7aad46d57b63fa2ff57d03a902bfde4821ad74b20bfe20d41e389_s390x as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/dex-rhel8@sha256:fdb439b295b3903f9f2341929a545366ebb35e38bdb5f609f31678b0edff357e_arm64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/gitops-operator-bundle@sha256:ed2a8efb4fc40d2d6a09ceecaa0f16d6bea139e2d7afae6ba85dbae356daf59b_amd64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/gitops-rhel8-operator@sha256:365cd33870134af2c4f2413797cf32d3bc0643e93581e9e7b4eede391d4a20e5_arm64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/gitops-rhel8-operator@sha256:630b22b7518a2355492d98f7ac5c05610c981f706f707f1bb82c2ad5c0493640_ppc64le as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/gitops-rhel8-operator@sha256:957b420874020d5db2a4d4cdfdab41cda7853695cd29494cba78712d01f43cc5_s390x as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/gitops-rhel8-operator@sha256:f4fed927355e4b6b53448194e5325b209738fc9ba990d02db4cb75653a878113_amd64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/gitops-rhel8@sha256:95f09ae4939c63ce698ac4a8b2b4275ebf2c304f3364bfc365c323aafbdd6206_arm64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/gitops-rhel8@sha256:b6c20bfad0e77414638d912d7cae7ff54ce0be30030fa9ba6f13448966c56294_ppc64le as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/gitops-rhel8@sha256:ead329586aa61f94bf8c8a0efb676e8a695fceef5fcacdc568a4a466b492ec5e_s390x as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/gitops-rhel8@sha256:f658538471aca8330a9d368f2cd3444416dca9a73e3cfb53b735da6463dcf337_amd64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/kam-delivery-rhel8@sha256:2c8c4d322736fe778a348e1dcd98f8f580b7f98ea42a651ad8b88c0d63f1b38d_arm64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/kam-delivery-rhel8@sha256:523a76e2f894264701c5e4c02c70b187abb5b3f58136b91bcafbbae3b48eca84_s390x as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/kam-delivery-rhel8@sha256:76e7ce8466895cfc12f4f6a024f54674006eaa92b05534685f04089e13eb1364_ppc64le as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/kam-delivery-rhel8@sha256:c01d39107b2d2449f86ce893c97e790ea6acfa37e69f7d3b70a795ceacec12b6_amd64 as a component of Red Hat OpenShift GitOps 1.10
- +4 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2024:2817
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.openshift.com/gitops/1.10/release_notes/gitops-release-notes.html
- externalhttps://docs.openshift.com/gitops/1.10/understanding_openshift_gitops/about-redhat-openshift-gitops.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270863
- externalhttps://issues.redhat.com/browse/GITOPS-4226
- externalhttps://issues.redhat.com/browse/GITOPS-4513
- externalhttps://issues.redhat.com/browse/GITOPS-4543
- externalhttps://issues.redhat.com/browse/GITOPS-4645
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2817.json