First published: Thu Jul 18 2024(Updated: )
Errata Advisory for Red Hat OpenShift GitOps v1.11.6<br>Security Fix(es):<br><li> openshift-gitops-argocd-container: golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON [gitops-1.11](CVE-2024-24786)</li> <li> openshift-gitops-argocd-container: helm: Missing YAML Content Leads To Panic [gitops-1.11](CVE-2024-26147)</li> <li> openshift-gitops-argocd-container: helm: Dependency management path traversal [gitops-1.11](CVE-2024-25620)</li> <li> Multiple CVEs in openshift-gitops-redis container</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Red Hat OpenShift GitOps for IBM Z and LinuxONE | ||
Red Hat Red Hat OpenShift GitOps | ||
Red Hat Red Hat OpenShift GitOps for ARM 64 | ||
Red Hat Red Hat OpenShift GitOps for IBM Power, little endian |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.