RHSA-2024:0692: Critical: Errata Advisory for Red Hat OpenShift GitOps 1.10.2 security update
RErrata Advisory for Red Hat OpenShift GitOps v1.10.2.<br>Security Fix(es):<br><li> argo-cd: vulnerable to a cross-server request forgery (CSRF)</li> attack (CVE-2024-22424)<br><li> go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients (CVE-2023-49569)</li> <li> go-git: Maliciously crafted Git server replies can cause DoS on go-git clients (CVE-2023-49568)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s)<br>listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What are the main vulnerabilities addressed in RHSA-2024:0692?
RHSA-2024:0692 addresses a cross-server request forgery (CSRF) vulnerability in argo-cd and a path traversal leading to remote code execution (RCE) vulnerability in go-git clients.
How can I mitigate the risks associated with RHSA-2024:0692?
To mitigate risks, it is recommended to update to the latest versions of Red Hat OpenShift GitOps that include the security fixes.
What systems are affected by the RHSA-2024:0692 advisory?
The RHSA-2024:0692 advisory affects Red Hat OpenShift GitOps v1.10.2 and its components.
Is there a recommended action for users of argo-cd regarding RHSA-2024:0692?
Users of argo-cd are advised to implement the security updates provided in RHSA-2024:0692 to protect against CSRF attacks.
What specific vulnerability is noted in go-git as per RHSA-2024:0692?
The specific vulnerability noted in go-git is that maliciously crafted Git server replies can lead to path traversal and remote code execution.