RHSA-2024:4973: Important: Errata Advisory for Red Hat OpenShift GitOps v1.12.5 security update
Errata Advisory for Red Hat OpenShift GitOps v1.12.5.Security Fix(es): openshift-gitops-argocd-container: Unauthenticated Denial of Service Vulnerability via /api/webhook Endpoint in Argo CD gitops-1.12 openshift-gitops-container: Argo CD web terminal session doesn't expire gitops-1.12 For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s)listed in the References section.
Other sources
Important: Errata Advisory for Red Hat OpenShift GitOps v1.12.5 security update
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:4973?
The severity of RHSA-2024:4973 is classified as Important due to an unauthenticated denial of service vulnerability.
How do I fix RHSA-2024:4973?
To fix RHSA-2024:4973, update your Red Hat OpenShift GitOps installation to the latest version where the vulnerability is patched.
What vulnerability is addressed in RHSA-2024:4973?
RHSA-2024:4973 addresses an unauthenticated denial of service vulnerability via the /api/webhook endpoint in Argo CD.
Which products are affected by RHSA-2024:4973?
The affected products by RHSA-2024:4973 include various versions of Red Hat OpenShift GitOps for ARM 64, IBM Power, IBM Z, and LinuxONE.
Is there a workaround for RHSA-2024:4973?
There are currently no official workarounds provided for RHSA-2024:4973, and the recommended action is to apply the necessary updates.