Red Hat Security Advisory: Errata Advisory for Red Hat OpenShift GitOps v1.11.6 security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-25620 — helm: Dependency management path traversal CVE-2024-26147 — helm: Missing YAML Content Leads To Panic
🎯 Affected products34
- Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/argo-rollouts-rhel8@sha256:076add1204be36717a4f21320e25a1ef8f362b898a91860101e036585bd7e75e_arm64 as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/argo-rollouts-rhel8@sha256:93f63395cd0e2d8bd35e1d7d5187f65bdd8efc9b564c98a2e07ba875aa887da4_amd64 as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/argo-rollouts-rhel8@sha256:9d59ac72c98079a9b29ed9a1ff5b39c49a804e28fb344112454c902000417090_ppc64le as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/argo-rollouts-rhel8@sha256:f40c487b2922ed5b109a036996c3800fa24a8ab40579a8184bd08c0fa0a0a82b_s390x as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/argocd-rhel8@sha256:95a36f983a5f2811f0fef486e90b84081d9dffeffe032be6cddeddfa4592e423_arm64 as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/argocd-rhel8@sha256:af69609ef177ee3cea8ef04a056df8a4a422dbc83a2631781589b61c1ed6dea6_ppc64le as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/argocd-rhel8@sha256:b2fbdc3c9926b23f7e8506ad6a7062e6ca326bb3b69984762f7e4f29b1f4f93c_amd64 as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/argocd-rhel8@sha256:f10e4081655abf6e5c99ad32000fe98f06299cbe55434908d3161d072fde2c20_s390x as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/console-plugin-rhel8@sha256:5beea6b8cdb9e06fb0fb7f92beaf02a9e9ba7b8794df8fc6eaa279c861c54c1f_ppc64le as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/console-plugin-rhel8@sha256:98de5f96397f94c776a44554da00e80fee544a424404b4b64e91c65f6e463c5d_amd64 as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/console-plugin-rhel8@sha256:f804b7d402d3cfb45223e011912711bdd79d792e87e96ee6e8738f41e2bdd545_arm64 as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/console-plugin-rhel8@sha256:f9f4c3dc50ed732bd52ca77cd81adf56228772ace9792bbd8ac72714282db5ea_s390x as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/dex-rhel8@sha256:7a0eaaa28b1593222a089490bbe785519bad33dc1169982fbd54d3c971589409_arm64 as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/dex-rhel8@sha256:82d2a3ab03d511f5751d154159e80170e47ee55789d6cfba9d9237d16a1c42fb_ppc64le as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/dex-rhel8@sha256:a9f2a4c1d771f91ed46acd849a2957fb984eecf2036d9b9c84f72847e1079d78_s390x as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/dex-rhel8@sha256:c9f1b0a58cefffb1aaa5e0eeb5e26ad1b24612f8b45987133cdb7fb4a0a98f5e_amd64 as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/gitops-operator-bundle@sha256:9357bd76c40ce6d7fdf72075b7a8c0fac132017390cdc3864768947b48347b94_amd64 as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/gitops-rhel8-operator@sha256:6bbc7f6e353d2d8cfcbcbb68472c97b6ff332c611780f645517a9d00937624f5_amd64 as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/gitops-rhel8-operator@sha256:8a0ff74e9378e2b1ba526b7bf4c7be033f22a4d4a4f40190a9e70b3306acf1be_ppc64le as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/gitops-rhel8-operator@sha256:ec259fd03d43f8c71dd136baa7058e038adc172ac41d9a0bda72d89075a2faca_arm64 as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/gitops-rhel8-operator@sha256:eef33c6fff1da9580c3b7003ecb3db73dc0af398b98f37639edf2af9cd21d0ec_s390x as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/gitops-rhel8@sha256:59bf2f19376abfeae9afd2abcd3fab5594c1fd1b98d221b142cf992348347ea8_s390x as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/gitops-rhel8@sha256:8a087169c5b03152752227249d862d824cd224bcd313e4894ad89a644f17c7d8_arm64 as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/gitops-rhel8@sha256:92a28af94fa2f0f47d38e573068876760dd5b89a605c186bdcf4a1191391fe64_amd64 as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/gitops-rhel8@sha256:9a5e3e6da074aff464456750cca74ca47a3ab7b635948ac4cb8eba77e91f5938_ppc64le as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/kam-delivery-rhel8@sha256:2b017899750d3945e786f75a85c9b0876bb9ee637c9c10b3f269a5976120776c_amd64 as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/kam-delivery-rhel8@sha256:6b4f257cf401049c9b8335a4c1f20ac8041a5e0d192279ead4fafbcd7e847e68_ppc64le as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/kam-delivery-rhel8@sha256:8078fdce62aaf915755f223a46f131cd683c4f52b1897300f2e51a164eec8e93_arm64 as a component of Red Hat OpenShift GitOps 1.11
- openshift-gitops-1/kam-delivery-rhel8@sha256:fbfa33cb3c73a0052b46562926e617e078709d8275555e80537b86d75a50ad0d_s390x as a component of Red Hat OpenShift GitOps 1.11
- +4 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: If a malicious plugin has been added which is causing all Helm client commands to panic, the malicious plugin can be manually removed from the filesystem. If using Helm SDK versions prior to 3.14.2, calls to affected functions can use recover to catch the panic.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2024:4626
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2264336
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265440
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268046
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4626.json