First published: Wed Oct 30 2024(Updated: )
Errata Advisory for Red Hat OpenShift GitOps v1.12.6.<br>Security Fix(es):<br><li> openshift-gitops-argocd-container: openshift-gitops-argocd-container: Denial of Service Vulnerability in body-parser [gitops-1.12](CVE-2024-45590) </li> <li> openshift-gitops-console-plugin-container: follow-redirects: Possible credential leak [gitops-1.12](CVE-2024-28849)</li> <li> openshift-gitops-dex-container: golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON [gitops-1.12](CVE-2024-24786)</li> <li> openshift-gitops-argocd-container: go-retryable<a href="http:" target="_blank">http:</a> url might write sensitive information to log file [gitops-1.12](CVE-2024-6104)</li> <li> openshift-gitops-argocd-container: Improper Sanitization in serve-static [gitops-1.12](CVE-2024-43800)</li> <li> openshift-gitops-argocd-container: Improper Input Handling in Express Redirects [gitops-1.12](CVE-2024-43796)</li> <li> openshift-gitops-argocd-container: Code Execution Vulnerability in Send Library [gitops-1.12](CVE-2024-43799)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Red Hat OpenShift GitOps for ARM 64 | ||
Red Hat Red Hat OpenShift GitOps | ||
Red Hat Red Hat OpenShift GitOps for IBM Power, little endian | ||
Red Hat Red Hat OpenShift GitOps for IBM Z and LinuxONE |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.