RHSA-2024:4972: Important: Errata Advisory for Red Hat OpenShift GitOps v1.11.7 security update
Errata Advisory for Red Hat OpenShift GitOps v1.11.7.Security Fix(es): openshift-gitops-argocd-container: Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in Argo CD gitops-1.11 openshift-gitops-container: Argo CD web terminal session doesn't expire gitops-1.11 For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Important: Errata Advisory for Red Hat OpenShift GitOps v1.11.7 security update
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What security vulnerabilities are addressed in RHSA-2024:4972?
RHSA-2024:4972 addresses an unauthenticated Denial of Service (DoS) vulnerability via the /api/webhook endpoint in Argo CD (CVE-2024-40634).
What is the severity of RHSA-2024:4972?
The severity of RHSA-2024:4972 is classified as important according to Red Hat's security advisory guidelines.
Which versions of Red Hat OpenShift GitOps are affected by RHSA-2024:4972?
RHSA-2024:4972 affects several versions of Red Hat OpenShift GitOps including v1.11.7 for various architectures.
How do I mitigate the vulnerabilities outlined in RHSA-2024:4972?
To mitigate the vulnerabilities detailed in RHSA-2024:4972, it is recommended to update to the patched version of the software provided in the advisory.
Is there a known fix for the vulnerabilities in RHSA-2024:4972?
Yes, the fix for the vulnerabilities in RHSA-2024:4972 typically involves updating to the latest secure version of Red Hat OpenShift GitOps as indicated in the advisory.