Red Hat Security Advisory: Red Hat OpenShift GitOps v1.20.4 security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation CVE-2026-32282 — golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root CVE-2026-42880 — argoproj/argo-cd: Argo CD: Information disclosure of Kubernetes Secret data via Server-Side Apply dry-run mechanism
🎯 Affected products42
- Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:4fc7f450ed27f228e9f3316c3132137b3afe7cf50a305e4dcaefd49f90a85117_amd64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:79678aa6a7a85a443fa63ca9ed51c009d1e82cda6094a53dfacc686f5276bda5_s390x as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:c09e60b8a28c54592e6a3ae888310fefaebe1baf41cc90fc054c15940e48f5f5_arm64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:d70756f5732cde032d921adc757cca39cd1711f421ed445bf26d7687b880f37f_ppc64le as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:4a679044f2c9531a5b093e74736b4c28c125485c66b8afd3fbc82f868b3b1136_arm64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:d86e912f9a3b81126e6aba09366e1aa3cc01c04cc1c256859b758300915be686_ppc64le as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:e395bde8aed3d4b96bb3c7dbcd3f482c8f3c1c8f3f7a0fd41001b1500b16ffe9_amd64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:f41409195124127b270fe99e62a3ed6da956dcc675e735316c155f26be6f25e2_s390x as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:0bc428c7968e0cdc1bd332dd622a26df0889213979547861733ae9cc898e37ad_s390x as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:c4c36dbf7f774c1a1f02b8d4fc2c3539daca7dee5db327fc168269e993aedd6e_ppc64le as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:de91f521e7442bb7f0b9a9d8991c1219bcb9029a5eaa9a65a8ffdf2dd4e7b140_arm64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:f960b8e8b4d2d05ce5f8ba1231149feaeb88ad966736315916838d28a260d2ea_amd64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:2c10fa9cb8012acd7768c1852239783d6e39e4b3845c180498179a9c275e1e78_arm64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:8b6661e4b32182e73a31330ce37e75c1e61186d5d11d64413545ef2396a891ff_s390x as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:9707ca205f8ef70c1c717b69def8a97fc073fb4f107a770bbae5052bd259e86e_amd64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:aa23e3d5ec1b30db7e637f872f68915c6b6144f1ebea8d229c54a79c92a84c7b_ppc64le as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:3892296394f7bad0156308d380b2d1460c487487fb4b63ee8c3ad7b721e79cc9_arm64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:517a98436c7ab863d0ecb5868767aa65b5b96cee51377ed9653014502f374040_amd64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:79d5b63a421a8115669b45adb68f9a8326a5cfd4bf8c9ed6a3c6bf3d8e000470_ppc64le as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:bdcc59168d4a265ef8733e8bd8991e0360bcdf0772531b2deb029f850877a2d7_s390x as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:03b2aecd6940db2ec188236c3c01a82aa837f8029842223814bea1ecfbbb8528_amd64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:1daea453dafe60848af52b13ffd92703cc826337ba38e8464888f9dc457288f6_s390x as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:3ecda0a790ad27a0ee994f20c57e67e084bbd6da7ca25606a571a4451441f666_arm64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:94dc69ec5613bb951d023fb8c3d02a24c22bdc8bbb43006a3545619eaa5aa76f_ppc64le as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:210616e4620edfe60d2afed74676e294b41b496e35a4d3c4632861e51219393e_arm64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:260a73551007abc59f7cdb4030b711788daf6d2f0fe3d21cf136df2ad301b40a_amd64 as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:6e451ed56c07de8809a97f00d16597fefeb0c0f26f15593191669eed58a61a70_s390x as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:73b63bcef874d439971678425fbeaf145d02843c2386417c3a28fca218f87b89_ppc64le as a component of Red Hat OpenShift GitOps 1.20
- registry.redhat.io/openshift-gitops-1/gitops-operator-bundle@sha256:b89210f76c58360210437f48dbde51d298ab1eb30cd2b77fb93c0e84dc8740c1_amd64 as a component of Red Hat OpenShift GitOps 1.20
- +12 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:20947
- externalhttps://access.redhat.com/security/cve/CVE-2026-32281
- externalhttps://access.redhat.com/security/cve/CVE-2026-32282
- externalhttps://access.redhat.com/security/cve/CVE-2026-42880
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_gitops/1.20/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_20947.json