A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network access to the Argo CD repo-server to achieve remote code execution. Under certain conditions, the attacker may then manipulate cached data to deploy malicious Kubernetes resources to managed clusters, potentially resulting in complete cluster compromise.
An update is now available for Red Hat OpenShift GitOps. Bug Fix(es) and Enhancement(s): GITOPS-9699 (CVE-2026-42880 Kubernetes Secret Extraction via ArgoCD ServerSideDiff [gitops-1.20])
Important: Red Hat OpenShift GitOps v1.18.2 security update
A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated permissions in other namespaces, including privileged namespaces. An authenticated attacker can then use these elevated permissions to create privileged workloads that run on master nodes, effectively giving them root access to the entire cluster.
An update is now available for Red Hat OpenShift GitOps.Security Fix(es): openshift-gitops-operator-container: Namespace Isolation Break gitops-1.16 Bug Fix(es): Gitops operator is not accepting regular expression in sourceNamespaces - Application in non-controlplane namespaces (GITOPS-6675) gitops-plugin Pods should comply with the Pod Security restricted policy (GITOPS-6777) Missing ArgoCD commit ID in UI (GITOPS-6896)
Important: Red Hat OpenShift GitOps 1.16.1 security release
Errata Advisory for Red Hat OpenShift GitOps v1.14.4 security release.Security Fix(es): openshift-gitops-argocd-container: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS) gitops-1.14 openshift-gitops-1/gitops-operator-bundle: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS) gitops-1.14 openshift-gitops-1/argocd-rhel9: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS) gitops-1.14 openshift-gitops-operator-container: Namespace Isolation Break gitops-1.14 openshift-gitops-dex-container: Unexpected memory consumption during token parsing in golang.org/x/oauth2 gitops-1.14 openshift-gitops-container: Potential denial of service in golang.org/x/crypto gitops-1.14 openshift-gitops-argo-rollouts-container: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS gitops-1.14 openshift-gitops-argocd-container: jwt-go allows excessive memory allocation during header parsing gitops-1.14 openshift-gitops-argocd-rhel9-container: jwt-go allows excessive memory allocation during header parsing gitops-1.14 openshift-gitops-argocd-container: Prototype Pollution in redoc gitops-1.14 openshift-gitops-argocd-rhel9-container: Prototype Pollution in redoc gitops-1.14
Errata Advisory for Red Hat OpenShift GitOps 1.15.3 security release.Security Fix(es): openshift-gitops-argocd-container: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS) gitops-1.15 openshift-gitops-1/argocd-rhel9: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS) gitops-1.15 openshift-gitops-1/gitops-operator-bundle: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS) gitops-1.15
Errata Advisory for Red Hat OpenShift GitOps v1.16.1 security release.Security Fix(es): openshift-gitops-argocd-container: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS) gitops-1.16 openshift-gitops-1/gitops-operator-bundle: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS) gitops-1.16
Errata Advisory for Red Hat OpenShift GitOps 1.15.2 release<br>Security Fix(es):<br><li> openshift-gitops-operator-container: Namespace Isolation Break gitops-1.15 </li> <li> openshift-gitops-argocd-container: Go JOSE's Parsing Vulnerable to Denial of Service gitops-1.15 </li> <li> openshift-gitops-argocd-rhel9-container: Go JOSE's Parsing Vulnerable to Denial of Service gitops-1.15 </li> <li> openshift-gitops-dex-container: Go JOSE's Parsing Vulnerable to Denial of Service gitops-1.15 </li> <li> openshift-gitops-operator-bundle-container: Go JOSE's Parsing Vulnerable to Denial of Service gitops-1.15 </li> <li> openshift-gitops-container: Potential denial of service in golang.org/x/crypto gitops-1.15 </li> <li> openshift-gitops-argo-rollouts-container: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS gitops-1.15 </li> <li> openshift-gitops-argocd-container: Memory Exhaustion in Expr Parser with Unrestricted Input gitops-1.15 </li> <li> openshift-gitops-argocd-rhel9-container: Memory Exhaustion in Expr Parser with Unrestricted Input gitops-1.15 </li> <li> openshift-gitops-argocd-container: jwt-go allows excessive memory allocation during header parsing gitops-1.15 </li> <li> openshift-gitops-argocd-rhel9-container: jwt-go allows excessive memory allocation during header parsing gitops-1.15 </li> <li> openshift-gitops-operator-bundle-container: jwt-go allows excessive memory allocation during header parsing gitops-1.15 </li> <li> openshift-gitops-argocd-container: Prototype Pollution in redoc gitops-1.15 </li> <li> openshift-gitops-argocd-rhel9-container: Prototype Pollution in redoc gitops-1.15 </li> <li> openshift-gitops-dex-container: Unexpected memory consumption during token parsing in golang.org/x/oauth2 gitops-1.15</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s)<br>listed in the References section.
Errata Advisory for Red Hat OpenShift GitOps v1.12.6.<br>Security Fix(es):<br><li> openshift-gitops-argocd-container: openshift-gitops-argocd-container: Denial of Service Vulnerability in body-parser gitops-1.12 </li> <li> openshift-gitops-console-plugin-container: follow-redirects: Possible credential leak gitops-1.12</li> <li> openshift-gitops-dex-container: golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON gitops-1.12</li> <li> openshift-gitops-argocd-container: go-retryable<a href="http:" target="blank">http:</a> url might write sensitive information to log file gitops-1.12</li> <li> openshift-gitops-argocd-container: Improper Sanitization in serve-static gitops-1.12</li> <li> openshift-gitops-argocd-container: Improper Input Handling in Express Redirects gitops-1.12</li> <li> openshift-gitops-argocd-container: Code Execution Vulnerability in Send Library gitops-1.12</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Errata Advisory for Red Hat OpenShift GitOps v1.13.2.<br>Security Fix(es):<br><li> openshift-gitops-argocd-container: Denial of Service Vulnerability in body-parser gitops-1.13</li> <li> openshift-gitops-argocd-container: Improper Input Handling in Express Redirects gitops-1.13</li> <li> openshift-gitops-argocd-container: Backtracking regular expressions cause ReDoS gitops-1.13</li> <li> openshift-gitops-argocd-container: Improper Sanitization in serve-static gitops-1.13</li> <li> openshift-gitops-argocd-container: Code Execution Vulnerability in Send Library gitops-1.13</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Errata Advisory for Red Hat OpenShift GitOps v1.11.7.Security Fix(es): openshift-gitops-argocd-container: Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint in Argo CD gitops-1.11 openshift-gitops-container: Argo CD web terminal session doesn't expire gitops-1.11 For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Errata Advisory for Red Hat OpenShift GitOps v1.12.5.Security Fix(es): openshift-gitops-argocd-container: Unauthenticated Denial of Service Vulnerability via /api/webhook Endpoint in Argo CD gitops-1.12 openshift-gitops-container: Argo CD web terminal session doesn't expire gitops-1.12 For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s)listed in the References section.
Errata Advisory for Red Hat OpenShift GitOps v1.13.1.Security Fix(es): openshift-gitops-argocd-container: Unauthenticated Denial of Service Vulnerability via /api/webhook Endpoint in Argo CD gitops-1.13 For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): In argoCD Version 2.11.3 webhook api endpoint is not working for Bitbucket and Azure DevOps
Moderate: Errata Advisory for Red Hat OpenShift GitOps v1.11.6 security update
Moderate: Errata Advisory for Red Hat OpenShift GitOps v1.12.4 security update
Errata Advisory for Red Hat OpenShift GitOps v1.11.5<br>Security Fix(es):<br><li> CVE-2024-31989 argocd: An update is now available for Red Hat OpenShift GitOps v1.11.5 to address the CVE-2024-31989, unprivileged pod in a different namespace on the same cluster could connect to the Redis server on port 6379.</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Errata Advisory for Red Hat OpenShift GitOps v1.10.6<br>Security Fix(es):<br><li> CVE-2024-31989 argocd: unprivileged pod in a different namespace on the same cluster could connect to the Redis server on port 6379.</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Errata Advisory for Red Hat OpenShift GitOps v1.12.3<br>Security Fix(es):<br><li> CVE-2024-31989 argocd: unprivileged pod in a different namespace on the same cluster could connect to the Redis server.</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Errata Advisory for Red Hat OpenShift GitOps v1.12.2.Security Fix(es): argo-cd: webpack-dev-middleware: lack of URL validation may lead to file leak (CVE-2024-29180). argo-cd: API server does not enforce project sourceNamespaces (CVE-2024-31990). For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es):1. Fix for a critical bug reported by customers where IgnoreDifferences Option in Sync Options was not working for array fields in ArgoCD. This fix will allow the users to ignore specific fields in the array when specified in ignoreDifferences during Sync.2. Added support for rollouts in gitops-must-gather which will allow customers to gather data and logs about their rollout installation.3. A fix that enables customer to add clusters hosted on GCP to ArgoCD.4. A fix to allow users to configure Notification Context in NotificationsConfigurationCR.5. Another fix to enable scheduling console-plugin workloads on Infra nodes.6. A fix to resolve customer bug which will now allow the users to create ArgoCD from Developer Console.7. An important customer fix that ensures that Argo CD correctly reports support for these host key algorithms during the handshake process, allowing the pull from Azure DevOps Repos to succeed.
Errata Advisory for Red Hat OpenShift GitOps v1.11.4.Security Fix(es): argo-cd: webpack-dev-middleware: lack of URL validation may lead to file leak (CVE-2024-29180) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es):1. Fix for a critical bug reported by customers where IgnoreDifferences Option in Sync Options was not working for array fields in ArgoCD. This fix will allow the users to ignore specific fields in the array when specified in ignoreDifferences during Sync.2. A fix that enables customer to add clusters hosted on GCP to ArgoCD.3. An important customer fix that ensures that Argo CD correctly reports support for these host key algorithms during the handshake process, allowing the pull from Azure DevOps Repos to succeed.
Errata Advisory for Red Hat OpenShift GitOps v1.10.5.<br>Security Fix(es):<br><li> argo-cd: webpack-dev-middleware: lack of URL validation may lead to file leak (CVE-2024-29180).</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br>1. Fix for a critical bug reported by customers where IgnoreDifferences Option<br>in Sync Options was not working for array fields in ArgoCD. This fix will allow the users to ignore specific fields in the array when specified in<br>ignoreDifferences during Sync.<br>2. A fix that enables customer to add clusters hosted on GCP to ArgoCD.<br>3. An important customer fix that ensures that Argo CD correctly reports support for these host key algorithms during the handshake process, allowing the pull from Azure DevOps Repos to succeed.
Errata Advisory for Red Hat OpenShift GitOps v1.12.1- Argo CD CLI and MicroShift GitOps.<br>Security Fix(es):<br><li> argo-cd: Denial of Service Due to Unsafe Array Modification in Multi-threaded Environment (CVE-2024-21661)</li> <li> argo-cd: Users with create but not override privileges can perform local</li> sync (CVE-2023-50726)<br><li> argo-cd: Bypassing Brute Force Protection via Application Crash and In-Memory Data Loss (CVE-2024-21652)</li> <li> argo-cd: uncontrolled resource consumption vulnerability (CVE-2024-29893)</li> <li> argo-cd: Bypassing Rate Limit and Brute Force Protection Using Cache Overflow (CVE-2024-21662)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Errata Advisory for Red Hat OpenShift GitOps v1.12.1.Security Fix(es): argo-cd: Denial of Service Due to Unsafe Array Modification in Multi-threaded Environment (CVE-2024-21661) argo-cd: Users with create but not override privileges can perform local sync (CVE-2023-50726) argo-cd: Bypassing Brute Force Protection via Application Crash and In-Memory Data Loss (CVE-2024-21652) argo-cd: uncontrolled resource consumption vulnerability (CVE-2024-29893) argo-cd: Bypassing Rate Limit and Brute Force Protection Using Cache Overflow (CVE-2024-21662) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Errata Advisory for Red Hat OpenShift GitOps v1.11.3.<br>Security Fix(es):<br><li> argo-cd: Denial of Service Due to Unsafe Array Modification in Multi-threaded</li> Environment (CVE-2024-21661)<br><li> argo-cd: Users with create but not override privileges can perform local</li> sync (CVE-2023-50726)<br><li> argo-cd: Bypassing Brute Force Protection via Application Crash and In-Memory</li> Data Loss (CVE-2024-21652)<br><li> argo-cd: uncontrolled resource consumption vulnerability (CVE-2024-29893)</li> <li> argo-cd: Bypassing Rate Limit and Brute Force Protection Using Cache Overflow</li> (CVE-2024-21662)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Errata Advisory for Red Hat OpenShift GitOps v1.10.4.<br>Security Fix(es):<br><li> argo-cd: Denial of Service Due to Unsafe Array Modification in Multi-threaded Environment (CVE-2024-21661)</li> <li> argo-cd: Users with create but not override privileges can perform local sync (CVE-2023-50726)</li> <li> argo-cd: Bypassing Brute Force Protection via Application Crash and In-Memory Data Loss (CVE-2024-21652)</li> <li> argo-cd: uncontrolled resource consumption vulnerability (CVE-2024-29893)</li> <li> argo-cd: Bypassing Rate Limit and Brute Force Protection Using Cache Overflow(CVE-2024-21662)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Errata Advisory for Red Hat OpenShift GitOps v1.12.0.Security Fix(es): argo-cd: XSS vulnerabilityin application summary component (CVE-2024-28175) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s)listed in the References section.
Important: Red Hat OpenShift GitOps security update
Important: Red Hat OpenShift GitOps security update