RHSA-2024:0691: Critical: Errata Advisory for Red Hat OpenShift GitOps v1.9.4 security update
Errata Advisory for Red Hat OpenShift GitOps v1.9.4.Security Fix(es): TRIAGE CVE-2024-22424 openshift-gitops-operator-container: argo-cd: vulnerable to a cross-server request forgery (CSRF) attack [gitops-1.9] CVE-2023-49568 openshift-gitops-container: go-git: Maliciously crafted Git server replies can cause DoS on go-git clients [gitops-1.9] CVE-2023-49569 openshift-gitops-container: go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients [gitops-1.9] CVE-2023-49568 openshift-gitops-argocd-container: go-git: Maliciously crafted Git server replies can cause DoS on go-git clients [gitops-1.9] For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s)listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0691?
RHSA-2024:0691 addresses critical vulnerabilities, including a CSRF vulnerability that could allow unauthorized actions.
How do I fix RHSA-2024:0691?
To fix RHSA-2024:0691, update your Red Hat OpenShift GitOps to the latest version as per the advisory recommendations.
What vulnerabilities are addressed in RHSA-2024:0691?
RHSA-2024:0691 addresses vulnerabilities including CVE-2024-22424 related to cross-server request forgery and CVE-2023-49568.
Which products are affected by RHSA-2024:0691?
RHSA-2024:0691 affects the Red Hat OpenShift GitOps product, particularly the argo-cd operator.
Is there a risk of exploitation from RHSA-2024:0691?
Yes, if not addressed, the vulnerabilities in RHSA-2024:0691 pose a significant risk of exploitation by attackers.