-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Critical: Red Hat OpenShift GitOps security update
Advisory ID:       RHSA-2023:5030-01
Product:           Red Hat OpenShift GitOps
Advisory URL:      https://access.redhat.com/errata/RHSA-2023:5030
Issue date:        2023-09-08
CVE Names:         CVE-2023-2602 CVE-2023-2603 CVE-2023-27536 
                   CVE-2023-28321 CVE-2023-28484 CVE-2023-29469 
                   CVE-2023-40029 CVE-2023-40584 
=====================================================================

1. Summary:

An update is now available for Red Hat OpenShift GitOps 1.8.

Red Hat Product Security has rated this update as having a security impact
of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Description:

Security Fix(es):

* ArgoCD: Secrets can be leaked through
kubectl.kubernetes.io/last-applied-configuration (CVE-2023-40029)

* ArgoCD: Denial of Service to Argo CD repo-server (CVE-2023-40584)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

4. Bugs fixed (https://bugzilla.redhat.com/):

2233203 - CVE-2023-40029 ArgoCD: secrets can be leak through kubectl.kubernetes.io/last-applied-configuration
2236530 - CVE-2023-40584 ArgoCD: Denial of Service to Argo CD repo-server

5. References:

https://access.redhat.com/security/cve/CVE-2023-2602
https://access.redhat.com/security/cve/CVE-2023-2603
https://access.redhat.com/security/cve/CVE-2023-27536
https://access.redhat.com/security/cve/CVE-2023-28321
https://access.redhat.com/security/cve/CVE-2023-28484
https://access.redhat.com/security/cve/CVE-2023-29469
https://access.redhat.com/security/cve/CVE-2023-40029
https://access.redhat.com/security/cve/CVE-2023-40584
https://access.redhat.com/security/updates/classification/#critical

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJk+3EmAAoJENzjgjWX9erEszMP/0sKqiLA7dlCSI+Qp8jyWmA7
5RpipG/S0cVrPV807vSIcKa3zQ2aYiaLNMO4hMb5FHcLBxKTvOvRR6WDoUzn+xo9
FYHjt3wKJiskPBj3YivqfQnlADkH2o22IVsvTOvs6pig1t+f6JYZepv3ov2a0bMh
mlN4TrfN7fpJE0NasweXe6rJAjcTenFgN/h5qh/3c+8z+8MWocjSI/8ttWj2ww7I
Mauma6/1gErJ7a+2bP9qfmhvy5B9vEZE8p2/ZRwNYXZYHZPl0gqH3yyes10+g0up
45fBN+bRrOW8cfZtEGg0DCyNkTfhmBQf/U/m0Ab4TGw+sAIpUyhVxSV7blwoGH45
0Cc6oAEp0syfFO7j14jKA8oZm3a0dfZUkQ2UeMe+q0jBqFER9WcSVumfxj7vqjx0
WcDnMLL0Vcp6zDBwDNjoAbvb5JY+WK2GGniVxat3u8n9Gh1hoU2Gkr+eTaGYF4iw
/v18MzQSnwNBeZAzzP+kfVJK/OhrgO3l5c3RSXDCWJP6B+qiz6j/G4VlYwKgwnT1
VqIHSq2EW5NbQUhoR4QkB0M0kIV/k3P3fUd135OW/yEvxrVw0K/10Od+KDZ+2HLw
AQtgMkWUA1dKEkBhE1WMglhJhbyvXXtHMtsfYveUC1DLB8vLGjYrqfy7RLkJm6Nq
hsfX5b3PH0pWF0KHgaLp
=5jcp
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2023-5030:01 Critical: Red Hat OpenShift GitOps security update

An update is now available for Red Hat OpenShift GitOps 1.8

Summary

Security Fix(es):
* ArgoCD: Secrets can be leaked through kubectl.kubernetes.io/last-applied-configuration (CVE-2023-40029)
* ArgoCD: Denial of Service to Argo CD repo-server (CVE-2023-40584)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2023-2602 https://access.redhat.com/security/cve/CVE-2023-2603 https://access.redhat.com/security/cve/CVE-2023-27536 https://access.redhat.com/security/cve/CVE-2023-28321 https://access.redhat.com/security/cve/CVE-2023-28484 https://access.redhat.com/security/cve/CVE-2023-29469 https://access.redhat.com/security/cve/CVE-2023-40029 https://access.redhat.com/security/cve/CVE-2023-40584 https://access.redhat.com/security/updates/classification/#critical

Package List


Severity
Advisory ID: RHSA-2023:5030-01
Product: Red Hat OpenShift GitOps
Advisory URL: https://access.redhat.com/errata/RHSA-2023:5030
Issued Date: : 2023-09-08
CVE Names: CVE-2023-2602 CVE-2023-2603 CVE-2023-27536 CVE-2023-28321 CVE-2023-28484 CVE-2023-29469 CVE-2023-40029 CVE-2023-40584

Topic

An update is now available for Red Hat OpenShift GitOps 1.8.Red Hat Product Security has rated this update as having a security impactof Critical. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

2233203 - CVE-2023-40029 ArgoCD: secrets can be leak through kubectl.kubernetes.io/last-applied-configuration

2236530 - CVE-2023-40584 ArgoCD: Denial of Service to Argo CD repo-server


Related News