RHSA-2025:8278: Important: Errata Advisory for Red Hat OpenShift GitOps v1.16.1 security update
Errata Advisory for Red Hat OpenShift GitOps v1.16.1 security release.Security Fix(es): openshift-gitops-argocd-container: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS) gitops-1.16 openshift-gitops-1/gitops-operator-bundle: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS) gitops-1.16
Other sources
Important: Errata Advisory for Red Hat OpenShift GitOps v1.16.1 security update
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:8278?
The severity of RHSA-2025:8278 is classified as important due to the improper URL sanitization vulnerability allowing cross-site scripting (XSS).
How do I fix RHSA-2025:8278?
To fix RHSA-2025:8278, update your Red Hat OpenShift GitOps installation to the latest patch version provided in the advisory.
What products are affected by RHSA-2025:8278?
RHSA-2025:8278 affects Red Hat OpenShift GitOps for ARM 64, IBM Z and LinuxONE, IBM Power little endian, and the standard Red Hat OpenShift GitOps product.
What is CVE-2025-47933 related to RHSA-2025:8278?
CVE-2025-47933 is associated with improper URL sanitization in the Argo CD Repository page, leading to potential XSS vulnerabilities.
Is there a workaround for RHSA-2025:8278?
Currently, the recommended action for RHSA-2025:8278 is to apply the security update, and there are no documented workarounds.