Red Hat Security Advisory: Errata Advisory for Red Hat OpenShift GitOps v1.12.4 security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-25620 — helm: Dependency management path traversal CVE-2024-26147 — helm: Missing YAML Content Leads To Panic
🎯 Affected products36
- Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/argo-rollouts-rhel8@sha256:03a9a34183ed581ef6c37bfd2628fa5cac699deb1dbccfa69f4ffa7c8bd5cdfa_s390x as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/argo-rollouts-rhel8@sha256:9a9553e940da983030f1d06b1a73afbbe69dd2afbaf35aca85d022786810891e_ppc64le as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/argo-rollouts-rhel8@sha256:aa3b1517f6b15456d6ca8796379aa9318fd349027ec05aa7bdc1123719b60f16_amd64 as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/argo-rollouts-rhel8@sha256:e6f8fe1d2e92dd4af70e2065cf12f523c09ed6f507dcbb5b1cde74281a5a7c29_arm64 as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/argocd-rhel8@sha256:3f7a36417f2244c65c594c1ba27dfe27c481ddc9cd77b6725bea34ffffa7c094_arm64 as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/argocd-rhel8@sha256:981f233c89dc451d6d4773888f3aeaf467856bfe4b6e599e1dc36ce949ff1e94_s390x as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/argocd-rhel8@sha256:c60b04f5b7603e1ab96648db23d95ac95c2548facae1c1252acf634a42fb411d_amd64 as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/argocd-rhel8@sha256:d88f18509bc4eba0e0b6e8c914f3c653a62d478ccddb836857da3dc250751537_ppc64le as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/argocd-rhel9@sha256:c89c5f5c91dfdc7fe821878c113bd49e3150eab70e6b6792b79e03b6159a1ba3_amd64 as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/argocd-rhel9@sha256:e98f1849f7a3bb3642ef4974b3005780abe91a6542e96eb81745aa25fdebe8df_arm64 as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/console-plugin-rhel8@sha256:13ba08737b47085c9fdb2430f1ec7d21d8954ac54d71f2cb4964886f683247ab_arm64 as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/console-plugin-rhel8@sha256:28daa3253c3bccc8b661c40abd04c87dfa498e04821d30ea3036312b76fe5a4e_amd64 as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/console-plugin-rhel8@sha256:9ec2cd87111e0cec02104604c8e95c9cb63aae9a44303fb6ebfd6d55f689591e_s390x as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/console-plugin-rhel8@sha256:d77164505154f55d8e67a2d90e7657b0ca6135bcb15458336bc50096f78eec5e_ppc64le as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/dex-rhel8@sha256:6e4ff694e827da331903dfaeeb2bbe0fbf259e22c5fdde0c5253163ec45e4a10_s390x as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/dex-rhel8@sha256:b300a9c26f0c00a7f90bb74877ab9b27fe8ff018a3cd2ad718be179cd96e651a_ppc64le as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/dex-rhel8@sha256:ebb14930583daf011b306fabc9c67687c6ef263f17dd1a9095fabe52847a6425_amd64 as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/dex-rhel8@sha256:f8bc86210129a6175f03d583a8afa9fb119fce94151dfadbaa1e36c0b02c3272_arm64 as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/gitops-operator-bundle@sha256:9bb74df8ca3491846b6df8313c96f99d58334c1bee8004f816777c39838ae54a_amd64 as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/gitops-rhel8-operator@sha256:10b81029e3248a29f6d5197abb06d11224ce2473f5e37b1cbb3d7c0ecaa740da_arm64 as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/gitops-rhel8-operator@sha256:2ebc3132162b1bb7cd2deedcda77552b2611e3cfb13d236d015bdd1aa5caadac_ppc64le as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/gitops-rhel8-operator@sha256:ad44cf803432d8edef7b01f6690bdcba40a2e7de11fa449aa5088e7e64eb32df_s390x as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/gitops-rhel8-operator@sha256:c321a8b1eeca0560e647df668c780e443d81555ab433613000993689a7fe7e02_amd64 as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/gitops-rhel8@sha256:146022a7303958f0117d5a727c8a57560a90bf6884b8ccaff4b86700cb9cec68_s390x as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/gitops-rhel8@sha256:93f89ba5dc766ad377bbe00c44850b814deaa4e66c64c665fbee12433f41819c_amd64 as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/gitops-rhel8@sha256:ae59a9812bf7e68d80702d76065b1a88a49477adcbc415cd51836bdefbd623ad_ppc64le as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/gitops-rhel8@sha256:ef8468c42e18c898f413670aa5ec63253d68ad0acbaf4ff4a05007c452e63dff_arm64 as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/kam-delivery-rhel8@sha256:107fa77ba6a551e324fcf7339b3cedfe2a47a669a59adf4a6559d187ea723850_amd64 as a component of Red Hat OpenShift GitOps 1.12
- openshift-gitops-1/kam-delivery-rhel8@sha256:2d7e96f437a5c7ecdcdd1f6bdd1a9a9d512224aa1013d6f66e49146d0e5b39a0_ppc64le as a component of Red Hat OpenShift GitOps 1.12
- +6 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: If a malicious plugin has been added which is causing all Helm client commands to panic, the malicious plugin can be manually removed from the filesystem. If using Helm SDK versions prior to 3.14.2, calls to affected functions can use recover to catch the panic.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2024:4163
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2264336
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265440
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268046
- externalhttps://issues.redhat.com/browse/GITOPS-4758
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4163.json