-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Important: Red Hat OpenShift GitOps security update
Advisory ID:       RHSA-2023:0467-01
Product:           Red Hat OpenShift GitOps
Advisory URL:      https://access.redhat.com/errata/RHSA-2023:0467
Issue date:        2023-01-25
CVE Names:         CVE-2021-46848 CVE-2022-3821 CVE-2022-35737 
                   CVE-2022-40303 CVE-2022-40304 CVE-2022-42010 
                   CVE-2022-42011 CVE-2022-42012 CVE-2022-43680 
                   CVE-2023-22482 CVE-2023-22736 
====================================================================
1. Summary:

An update is now available for Red Hat OpenShift GitOps 1.7.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Description:

Red Hat Openshift GitOps is a declarative way to implement continuous
deployment for cloud native applications.

Security Fix(es):

* ArgoCD: JWT audience claim is not verified (CVE-2023-22482)

* ArgoCD: authorization bypass (CVE-2023-22736)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

4. Bugs fixed (https://bugzilla.redhat.com/):

2160492 - CVE-2023-22482 ArgoCD: JWT audience claim is not verified
2162517 - CVE-2023-22736 argocd: Controller reconciles apps outside configured namespaces when sharding is enabled

5. References:

https://access.redhat.com/security/cve/CVE-2021-46848
https://access.redhat.com/security/cve/CVE-2022-3821
https://access.redhat.com/security/cve/CVE-2022-35737
https://access.redhat.com/security/cve/CVE-2022-40303
https://access.redhat.com/security/cve/CVE-2022-40304
https://access.redhat.com/security/cve/CVE-2022-42010
https://access.redhat.com/security/cve/CVE-2022-42011
https://access.redhat.com/security/cve/CVE-2022-42012
https://access.redhat.com/security/cve/CVE-2022-43680
https://access.redhat.com/security/cve/CVE-2023-22482
https://access.redhat.com/security/cve/CVE-2023-22736
https://docs.openshift.com/gitops/1.11/understanding_openshift_gitops/about-redhat-openshift-gitops.html
https://access.redhat.com/security/updates/classification/#important

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBY9GucdzjgjWX9erEAQh86w//faaz9Ywaa6wfhtz+5MrYTWddEx8DKiek
Kb5/Hk9T2czE1HJVAKhh9iWSkBlGtTeEAkSmRohFOrElF5VJ5CVfalnDS3x2W6VV
KMf+Qnrw1+apt3BA+yNQA4KAvwIVL9/+QS0c0UsakWTtrY+cSLwDEIIzcXFJbL1I
R3UAAoGwqk7Q2qS7x7Z1NrG+sOmkCa3q5WerKciQa8YVeLf5zwlq07sEFlpEfPMs
PLfIU0aHcceRqFv6NLl7Q1bABtPl3WrveRDaR8QA+sFvAR9X1wMT17Mfkfg0OzYj
v82Isvya5AYA5lP1cfPxVc7U3PG23x4JpJykn3khNpzdIHWHK8n8BZTIO3mXl3PX
3fPfLtcQ1M9LCb5ivnLiSsORxya7DoYFBjnL9o9ULyv8mwj2JfbtbVeTBkPzXEFK
xFI+Tl5bABdo0MJhrK8pbq/uV8I708QoznXSWB5Lq2WTz+xYItYXhAG4oPNVoaaR
cQeIu3i5VDi9VRaohotjMuxN7dXmZkwLJWQ55idKxk5Ul+L7DoLh0LMnVIXDMRV3
TfEFLFod/zt1yx2T9nqe33pCYJHLtFail24YjMpcFvvGXKKSioH9Y8DjHnUgCgz7
wuOGI3kxn9J8kL561UtKREIR6arNZR9Ht/zKXXF82uZnBT+KVCQX6M4TvNp/oaAD
wm5RXj9L40I=uoKQ
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2023-0467:01 Important: Red Hat OpenShift GitOps security

An update is now available for Red Hat OpenShift GitOps 1.7

Summary

Red Hat Openshift GitOps is a declarative way to implement continuous deployment for cloud native applications.
Security Fix(es):
* ArgoCD: JWT audience claim is not verified (CVE-2023-22482)
* ArgoCD: authorization bypass (CVE-2023-22736)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2021-46848 https://access.redhat.com/security/cve/CVE-2022-3821 https://access.redhat.com/security/cve/CVE-2022-35737 https://access.redhat.com/security/cve/CVE-2022-40303 https://access.redhat.com/security/cve/CVE-2022-40304 https://access.redhat.com/security/cve/CVE-2022-42010 https://access.redhat.com/security/cve/CVE-2022-42011 https://access.redhat.com/security/cve/CVE-2022-42012 https://access.redhat.com/security/cve/CVE-2022-43680 https://access.redhat.com/security/cve/CVE-2023-22482 https://access.redhat.com/security/cve/CVE-2023-22736 https://docs.openshift.com/gitops/1.11/understanding_openshift_gitops/about-redhat-openshift-gitops.html https://access.redhat.com/security/updates/classification/#important

Package List


Severity
Advisory ID: RHSA-2023:0467-01
Product: Red Hat OpenShift GitOps
Advisory URL: https://access.redhat.com/errata/RHSA-2023:0467
Issued Date: : 2023-01-25
CVE Names: CVE-2021-46848 CVE-2022-3821 CVE-2022-35737 CVE-2022-40303 CVE-2022-40304 CVE-2022-42010 CVE-2022-42011 CVE-2022-42012 CVE-2022-43680 CVE-2023-22482 CVE-2023-22736

Topic

An update is now available for Red Hat OpenShift GitOps 1.7.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

2160492 - CVE-2023-22482 ArgoCD: JWT audience claim is not verified

2162517 - CVE-2023-22736 argocd: Controller reconciles apps outside configured namespaces when sharding is enabled


Related News