RHSA-2025:9506: Red Hat OpenShift GitOps security update
An update is now available for Red Hat OpenShift GitOps.Security Fix(es): openshift-gitops-operator-container: Namespace Isolation Break gitops-1.16 Bug Fix(es): Gitops operator is not accepting regular expression in sourceNamespaces - Application in non-controlplane namespaces (GITOPS-6675) gitops-plugin Pods should comply with the Pod Security restricted policy (GITOPS-6777) Missing ArgoCD commit ID in UI (GITOPS-6896)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
openshift-gitops-operator-containerto a version that resolves this vulnerability.Fixed in gitops-1.16Patch CVE-2024-13484 - Upgrade
Upgrade
openshift-gitops-operator-containerto a version that resolves this vulnerability.Patch GITOPS-6675 - Upgrade
Upgrade
openshift-gitops-operator-containerto a version that resolves this vulnerability.Patch GITOPS-6777 - Upgrade
Upgrade
openshift-gitops-operator-containerto a version that resolves this vulnerability.Patch GITOPS-6896
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:9506?
RHSA-2025:9506 addresses a security vulnerability classified as a Namespace Isolation Break.
How do I fix RHSA-2025:9506?
To resolve RHSA-2025:9506, you should apply the latest updates available for Red Hat OpenShift GitOps.
What is the impact of CVE-2024-13484?
CVE-2024-13484 can lead to the potential unauthorized access to or manipulation of resources in the affected namespace.
Is there a workaround for RHSA-2025:9506?
There are no recommended workarounds for RHSA-2025:9506; applying the update is the best course of action.
When was RHSA-2025:9506 released?
RHSA-2025:9506 was released to address a vulnerability in Red Hat OpenShift GitOps on a specified release date.