Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Red Hat OpenShift GitOps 1.6 RHSA-2023:1453-01 Moderate: API Enumeration

Redhat Large Esm H500
An update is now available for Red Hat OpenShift GitOps 1.6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: Red Hat OpenShift GitOps security update
Advisory ID:       RHSA-2023:1453-01
Product:           Red Hat OpenShift GitOps
Advisory URL:      https://access.redhat.com/errata/RHSA-2023:1453
Issue date:        2023-03-23
CVE Names:         CVE-2020-10735 CVE-2021-28861 CVE-2022-1471 
                   CVE-2022-4415 CVE-2022-34174 CVE-2022-40897 
                   CVE-2022-41354 CVE-2022-45061 CVE-2022-48303 
                   CVE-2023-23916 
====================================================================
1. Summary:

An update is now available for Red Hat OpenShift GitOps 1.6.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Description:

Security Fix(es):

* ArgoCD: Authenticated but unauthorized users may enumerate Application
names via the API (CVE-2022-41354)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

4. Bugs fixed (https://bugzilla.redhat.com/):

2167820 - CVE-2022-41354 ArgoCD: Authenticated but unauthorized users may enumerate Application names via the API

5. References:

https://access.redhat.com/security/cve/CVE-2020-10735
https://access.redhat.com/security/cve/CVE-2021-28861
https://access.redhat.com/security/cve/CVE-2022-1471
https://access.redhat.com/security/cve/CVE-2022-4415
https://access.redhat.com/security/cve/CVE-2022-34174
https://access.redhat.com/security/cve/CVE-2022-40897
https://access.redhat.com/security/cve/CVE-2022-41354
https://access.redhat.com/security/cve/CVE-2022-45061
https://access.redhat.com/security/cve/CVE-2022-48303
https://access.redhat.com/security/cve/CVE-2023-23916
https://access.redhat.com/security/updates/classification#moderate

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact

Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBZBzBgdzjgjWX9erEAQhjSBAAh7FvU63tYvcvm9mNr5i4LKeWWbC/otaD
22vtAruUsqWAWLcC2egZMAnYp4lfz0CXyLuz4rQs5rDo5ZCOdREUea57WYrluTkg
cD99cKAiyO30YRkBw8jgtu4ZBOb60tuv+mYWfJzA9/LprYvL+CVgoUaQ1XqviAXq
89dUOSIX1Kc/wMsPkMGzWqiF3c9ai5tCIvW2s9yhFumlFFLdKfvU1ZEoXLGjYs3a
c9CeZlKkhORIQi45197QVDdy/sKW+/aDyojEIUAAw+w8ZHEbNFNQwwwGApHVzOsf
lul6WYoiwwXXBiFMz6fkjo1SmTQIljI2hbW7qphObs8wXDBWzvIuFR3uDEklJMJu
jNuflBhhBso7yx6xRVp/CaTdGr1rR1kNGbqQs3QRlj6KgOsZNaUm86GMF1CoUnFt
0iXMG5gWsn/nJnGor2SgpuJRfMQwjmfp4DO8KIoTWoQ8b7fnLE9jtTerudJiIobk
U5ysjS66ytAqCILyWCvCsJT+L2jLY4oraAyJAyrYVjrIIcHO6T84OnpvqZaZy1ok
Q+I2h9pd5iIjbNWbIJBVje0NUFv/arcTDQDA+PLdZ3V+BK7gisnRHsVHRYUmVGa4
ZNLYDECKEy2CHaSTRlGAwjGoUpO0bZx2uVxyAqoVUDsOUvewgeUP/w7nTdkXX6zh
iFp64IHstt4=EYJ/
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
This email address is being protected from spambots. You need JavaScript enabled to view it.

Warning: Undefined array key "solution" in /var/www/www.linuxsecurity.com-443/html/lsadvisories/lsadvisories.php on line 316

Red Hat OpenShift GitOps 1.6 RHSA-2023:1453-01 Moderate: API Enumeration

red hat
Calendar Grey March 23, 2023
Dist Redhat Esm H88
A notable security update has been rolled out by Red Hat for OpenShift GitOps, tackling several vulnerabilities such as API exposure.
An update is now available for Red Hat OpenShift GitOps 1.6

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

Security Fix(es):
* ArgoCD: Authenticated but unauthorized users may enumerate Application names via the API (CVE-2022-41354)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2020-10735 https://access.redhat.com/security/cve/CVE-2021-28861 https://access.redhat.com/security/cve/CVE-2022-1471 https://access.redhat.com/security/cve/CVE-2022-4415 https://access.redhat.com/security/cve/CVE-2022-34174 https://access.redhat.com/security/cve/CVE-2022-40897 https://access.redhat.com/security/cve/CVE-2022-41354 https://access.redhat.com/security/cve/CVE-2022-45061 https://access.redhat.com/security/cve/CVE-2022-48303 https://access.redhat.com/security/cve/CVE-2023-23916 https://access.redhat.com/security/updates/classification#moderate

Package List


Advisory ID: RHSA-2023:1453-01
Product: Red Hat OpenShift GitOps
Issue date: 2023-03-23

Topic

An update is now available for Red Hat OpenShift GitOps 1.6.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures


Warning: Undefined array key "relevant_releases_architectures" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/34249_3e4bf4acb8c07dfea38b8147414a3c74 on line 11

Warning: Undefined array key "relevant_releases_architectures" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/34249_3e4bf4acb8c07dfea38b8147414a3c74 on line 16

Bugs Fixed

2167820 - CVE-2022-41354 ArgoCD: Authenticated but unauthorized users may enumerate Application names via the API

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here