Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Red Hat OpenShift GitOps RHSA-2023-5030-01 Critical: Secrets Leak, DoS

red hat
Calendar Grey September 8, 2023
Dist Redhat Esm H88
Important security patch released for Red Hat OpenShift GitOps tackling several vulnerabilities such as secret exposure and denial of service.
An update is now available for Red Hat OpenShift GitOps 1.8

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Summary

Security Fix(es):
* ArgoCD: Secrets can be leaked through kubectl.kubernetes.io/last-applied-configuration (CVE-2023-40029)
* ArgoCD: Denial of Service to Argo CD repo-server (CVE-2023-40584)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2023-2602 https://access.redhat.com/security/cve/CVE-2023-2603 https://access.redhat.com/security/cve/CVE-2023-27536 https://access.redhat.com/security/cve/CVE-2023-28321 https://access.redhat.com/security/cve/CVE-2023-28484 https://access.redhat.com/security/cve/CVE-2023-29469 https://access.redhat.com/security/cve/CVE-2023-40029 https://access.redhat.com/security/cve/CVE-2023-40584 https://access.redhat.com/security/updates/classification/#critical

Package List


Severity
critical
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2023:5030-01
Product: Red Hat OpenShift GitOps
Issue date: 2023-09-08

Topic

An update is now available for Red Hat OpenShift GitOps 1.8.Red Hat Product Security has rated this update as having a security impactof Critical. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Bugs Fixed

2233203 - CVE-2023-40029 ArgoCD: secrets can be leak through kubectl.kubernetes.io/last-applied-configuration

2236530 - CVE-2023-40584 ArgoCD: Denial of Service to Argo CD repo-server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here