Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Red Hat OpenShift GitOps: RHSA-2022:1041-01 Important Fix Security Issue

Redhat Large Esm H500
An update is now available for Red Hat OpenShift GitOps 1.4 OpenShift GitOps v1.4.4 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Important: Red Hat OpenShift GitOps security update
Advisory ID:       RHSA-2022:1041-01
Product:           Red Hat OpenShift GitOps
Advisory URL:      https://access.redhat.com/errata/RHSA-2022:1041
Issue date:        2022-03-23
CVE Names:         CVE-2021-3999 CVE-2021-23177 CVE-2021-31566 
                   CVE-2021-45960 CVE-2021-46143 CVE-2022-0261 
                   CVE-2022-0318 CVE-2022-0359 CVE-2022-0361 
                   CVE-2022-0392 CVE-2022-0413 CVE-2022-1025 
                   CVE-2022-22822 CVE-2022-22823 CVE-2022-22824 
                   CVE-2022-22825 CVE-2022-22826 CVE-2022-22827 
                   CVE-2022-23218 CVE-2022-23219 CVE-2022-23308 
                   CVE-2022-23852 CVE-2022-24407 CVE-2022-24730 
                   CVE-2022-24731 CVE-2022-25235 CVE-2022-25236 
                   CVE-2022-25315 
====================================================================
1. Summary:

An update is now available for Red Hat OpenShift GitOps 1.4

OpenShift GitOps v1.4.4

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Description:

Red Hat Openshift GitOps is a declarative way to implement continuous
deployment for cloud native applications.

Security Fix(es):

* Openshift-Gitops: Improper access control allows admin privilege
escalation
(CVE-2022-1025)

* argocd: path traversal and improper access control allows leaking
out-of-bound
files (CVE-2022-24730)

* argocd: path traversal allows leaking out-of-bound files (CVE-2022-24731)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

4. Bugs fixed (https://bugzilla.redhat.com/):

2062751 - CVE-2022-24730 argocd: path traversal and improper access control allows leaking out-of-bound files
2062755 - CVE-2022-24731 argocd: path traversal allows leaking out-of-bound files
2064682 - CVE-2022-1025 Openshift-Gitops: Improper access control allows admin privilege escalation

5. References:

https://access.redhat.com/security/cve/CVE-2021-3999
https://access.redhat.com/security/cve/CVE-2021-23177
https://access.redhat.com/security/cve/CVE-2021-31566
https://access.redhat.com/security/cve/CVE-2021-45960
https://access.redhat.com/security/cve/CVE-2021-46143
https://access.redhat.com/security/cve/CVE-2022-0261
https://access.redhat.com/security/cve/CVE-2022-0318
https://access.redhat.com/security/cve/CVE-2022-0359
https://access.redhat.com/security/cve/CVE-2022-0361
https://access.redhat.com/security/cve/CVE-2022-0392
https://access.redhat.com/security/cve/CVE-2022-0413
https://access.redhat.com/security/cve/CVE-2022-1025
https://access.redhat.com/security/cve/CVE-2022-22822
https://access.redhat.com/security/cve/CVE-2022-22823
https://access.redhat.com/security/cve/CVE-2022-22824
https://access.redhat.com/security/cve/CVE-2022-22825
https://access.redhat.com/security/cve/CVE-2022-22826
https://access.redhat.com/security/cve/CVE-2022-22827
https://access.redhat.com/security/cve/CVE-2022-23218
https://access.redhat.com/security/cve/CVE-2022-23219
https://access.redhat.com/security/cve/CVE-2022-23308
https://access.redhat.com/security/cve/CVE-2022-23852
https://access.redhat.com/security/cve/CVE-2022-24407
https://access.redhat.com/security/cve/CVE-2022-24730
https://access.redhat.com/security/cve/CVE-2022-24731
https://access.redhat.com/security/cve/CVE-2022-25235
https://access.redhat.com/security/cve/CVE-2022-25236
https://access.redhat.com/security/cve/CVE-2022-25315
https://access.redhat.com/security/updates/classification#important

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact

Copyright 2022 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBYjvl4NzjgjWX9erEAQjRzBAAgYdSY5r2cBqlMi2SWv6YDaQe4/tZUGbH
RsaRaP5+Vg6dMxWwBBzrGkniQa/ObxM4isQZTxbI6hgt8hqhFNQSCfqUV9k7l/40
+PCQoYtMG+KXeOic0+iwQb4qLYPpcchGU/FrFqJLbLIz4UeZjZ4Aols2J4iHqcDS
vhJiChwGAUUsjv45be7Got2iO2OYH/umt7R+92/6swUnIsoH2LBsJhiE1QoeCuL3
4cmy2AveprvmTqBDqBsfzNKhn3mSHoXFwaXBO3vNN2nUojso75/HVh8JiKrxDq9N
YfSAwyS0V2zS+ZNr84RCi3RcIpnjwBeBU9jK/hS6Oa22p92qUeqD7XZWBU9dLihh
coCApn9Uc5vCR0RwcEyEBkhrtyrAv4o35QZ9vNDEDw2QWblxM4dVRiZKEUmcVORR
VCkozbbEEkQKF2uzExr4QhSlm//qvUt6ODFeIVRS2QQcSBby7hHTGFvIzxaqlrJy
jz8UhYIwNyNnzkLkyszGRC9rfJ6ke8RdZtxUB+IpYvi0CO9NnIWn7v1f6Rv1s4Il
8P1BMPf+utbEwBniyMWEWG5fll3/a2LCwbPuO1oKKt91TGNpL3sKHYGbPpam4tks
qAxULk8B8sBQ5hXJ16BtWMXmfpr+Ax5/16AcWF89UdCxAW5TJ4g+RIH7KnO0va1v
jd/bgNGigkE=NMT0
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
This email address is being protected from spambots. You need JavaScript enabled to view it.
https://listman.redhat.com/mailman/listinfo/rhsa-announce

Warning: Undefined variable $read_more_reference in /var/www/www.linuxsecurity.com-443/html/lsadvisories/lsadvisories.php on line 1198

Red Hat OpenShift GitOps: RHSA-2022:1041-01 Important Fix Security Issue

red hat
Calendar Grey March 23, 2022
Dist Redhat Esm H88
An essential security patch has been released for Red Hat OpenShift GitOps to mitigate significant vulnerabilities and risks.
An update is now available for Red Hat OpenShift GitOps 1.4 OpenShift GitOps v1.4.4 Red Hat Product Security has rated this update as having a security impact of Important

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

Red Hat Openshift GitOps is a declarative way to implement continuous deployment for cloud native applications.
Security Fix(es):
* Openshift-Gitops: Improper access control allows admin privilege escalation (CVE-2022-1025)
* argocd: path traversal and improper access control allows leaking out-of-bound files (CVE-2022-24730)
* argocd: path traversal allows leaking out-of-bound files (CVE-2022-24731)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2021-3999 https://access.redhat.com/security/cve/CVE-2021-23177 https://access.redhat.com/security/cve/CVE-2021-31566 https://access.redhat.com/security/cve/CVE-2021-45960 https://access.redhat.com/security/cve/CVE-2021-46143 https://access.redhat.com/security/cve/CVE-2022-0261 https://access.redhat.com/security/cve/CVE-2022-0318 https://access.redhat.com/security/cve/CVE-2022-0359 https://access.redhat.com/security/cve/CVE-2022-0361 https://access.redhat.com/security/cve/CVE-2022-0392 https://access.redhat.com/security/cve/CVE-2022-0413 https://access.redhat.com/security/cve/CVE-2022-1025 https://access.redhat.com/security/cve/CVE-2022-22822 https://access.redhat.com/security/cve/CVE-2022-22823 https://access.redhat.com/security/cve/CVE-2022-22824 https://access.redhat.com/security/cve/CVE-2022-22825 https://access.redhat.com/security/cve/CVE-2022-22826 https://access.redhat.com/security/cve/CVE-2022-22827 https://access.redhat.com/security/cve/CVE-2022-23218 https://access.redhat.com/security/cve/CVE-2022-23219 https://access.redhat.com/security/cve/CVE-2022-23308 https://access.redhat.com/security/cve/CVE-2022-23852 https://access.redhat.com/security/cve/CVE-2022-24407 Read the Full Advisory

Package List


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2022:1041-01
Product: Red Hat OpenShift GitOps
Issue date: 2022-03-23

Topic

An update is now available for Red Hat OpenShift GitOps 1.4OpenShift GitOps v1.4.4Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures


Warning: Undefined array key "relevant_releases_architectures" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/107166_3e4bf4acb8c07dfea38b8147414a3c74 on line 11

Warning: Undefined array key "relevant_releases_architectures" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/107166_3e4bf4acb8c07dfea38b8147414a3c74 on line 16

Bugs Fixed

2062751 - CVE-2022-24730 argocd: path traversal and improper access control allows leaking out-of-bound files

2062755 - CVE-2022-24731 argocd: path traversal allows leaking out-of-bound files

2064682 - CVE-2022-1025 Openshift-Gitops: Improper access control allows admin privilege escalation

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here