-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: Red Hat OpenShift GitOps security update
Advisory ID:       RHSA-2023:1453-01
Product:           Red Hat OpenShift GitOps
Advisory URL:      https://access.redhat.com/errata/RHSA-2023:1453
Issue date:        2023-03-23
CVE Names:         CVE-2020-10735 CVE-2021-28861 CVE-2022-1471 
                   CVE-2022-4415 CVE-2022-34174 CVE-2022-40897 
                   CVE-2022-41354 CVE-2022-45061 CVE-2022-48303 
                   CVE-2023-23916 
====================================================================
1. Summary:

An update is now available for Red Hat OpenShift GitOps 1.6.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Description:

Security Fix(es):

* ArgoCD: Authenticated but unauthorized users may enumerate Application
names via the API (CVE-2022-41354)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

4. Bugs fixed (https://bugzilla.redhat.com/):

2167820 - CVE-2022-41354 ArgoCD: Authenticated but unauthorized users may enumerate Application names via the API

5. References:

https://access.redhat.com/security/cve/CVE-2020-10735
https://access.redhat.com/security/cve/CVE-2021-28861
https://access.redhat.com/security/cve/CVE-2022-1471
https://access.redhat.com/security/cve/CVE-2022-4415
https://access.redhat.com/security/cve/CVE-2022-34174
https://access.redhat.com/security/cve/CVE-2022-40897
https://access.redhat.com/security/cve/CVE-2022-41354
https://access.redhat.com/security/cve/CVE-2022-45061
https://access.redhat.com/security/cve/CVE-2022-48303
https://access.redhat.com/security/cve/CVE-2023-23916
https://access.redhat.com/security/updates/classification/#moderate

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBZBzBgdzjgjWX9erEAQhjSBAAh7FvU63tYvcvm9mNr5i4LKeWWbC/otaD
22vtAruUsqWAWLcC2egZMAnYp4lfz0CXyLuz4rQs5rDo5ZCOdREUea57WYrluTkg
cD99cKAiyO30YRkBw8jgtu4ZBOb60tuv+mYWfJzA9/LprYvL+CVgoUaQ1XqviAXq
89dUOSIX1Kc/wMsPkMGzWqiF3c9ai5tCIvW2s9yhFumlFFLdKfvU1ZEoXLGjYs3a
c9CeZlKkhORIQi45197QVDdy/sKW+/aDyojEIUAAw+w8ZHEbNFNQwwwGApHVzOsf
lul6WYoiwwXXBiFMz6fkjo1SmTQIljI2hbW7qphObs8wXDBWzvIuFR3uDEklJMJu
jNuflBhhBso7yx6xRVp/CaTdGr1rR1kNGbqQs3QRlj6KgOsZNaUm86GMF1CoUnFt
0iXMG5gWsn/nJnGor2SgpuJRfMQwjmfp4DO8KIoTWoQ8b7fnLE9jtTerudJiIobk
U5ysjS66ytAqCILyWCvCsJT+L2jLY4oraAyJAyrYVjrIIcHO6T84OnpvqZaZy1ok
Q+I2h9pd5iIjbNWbIJBVje0NUFv/arcTDQDA+PLdZ3V+BK7gisnRHsVHRYUmVGa4
ZNLYDECKEy2CHaSTRlGAwjGoUpO0bZx2uVxyAqoVUDsOUvewgeUP/w7nTdkXX6zh
iFp64IHstt4=EYJ/
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2023-1453:01 Moderate: Red Hat OpenShift GitOps security update

An update is now available for Red Hat OpenShift GitOps 1.6

Summary

Security Fix(es):
* ArgoCD: Authenticated but unauthorized users may enumerate Application names via the API (CVE-2022-41354)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2020-10735 https://access.redhat.com/security/cve/CVE-2021-28861 https://access.redhat.com/security/cve/CVE-2022-1471 https://access.redhat.com/security/cve/CVE-2022-4415 https://access.redhat.com/security/cve/CVE-2022-34174 https://access.redhat.com/security/cve/CVE-2022-40897 https://access.redhat.com/security/cve/CVE-2022-41354 https://access.redhat.com/security/cve/CVE-2022-45061 https://access.redhat.com/security/cve/CVE-2022-48303 https://access.redhat.com/security/cve/CVE-2023-23916 https://access.redhat.com/security/updates/classification/#moderate

Package List


Severity
Advisory ID: RHSA-2023:1453-01
Product: Red Hat OpenShift GitOps
Advisory URL: https://access.redhat.com/errata/RHSA-2023:1453
Issued Date: : 2023-03-23
CVE Names: CVE-2020-10735 CVE-2021-28861 CVE-2022-1471 CVE-2022-4415 CVE-2022-34174 CVE-2022-40897 CVE-2022-41354 CVE-2022-45061 CVE-2022-48303 CVE-2023-23916

Topic

An update is now available for Red Hat OpenShift GitOps 1.6.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

2167820 - CVE-2022-41354 ArgoCD: Authenticated but unauthorized users may enumerate Application names via the API


Related News