[RHSA-2023:1453-01] Moderate: Red Hat OpenShift GitOps security update
Security announcements for all Red Hat products and services.
rhsa-announce at redhat.com
Thu Mar 23 21:15:50 UTC 2023
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
=====================================================================
Red Hat Security Advisory
Synopsis: Moderate: Red Hat OpenShift GitOps security update
Advisory ID: RHSA-2023:1453-01
Product: Red Hat OpenShift GitOps
Advisory URL: https://access.redhat.com/errata/RHSA-2023:1453
Issue date: 2023-03-23
CVE Names: CVE-2020-10735 CVE-2021-28861 CVE-2022-1471
CVE-2022-4415 CVE-2022-34174 CVE-2022-40897
CVE-2022-41354 CVE-2022-45061 CVE-2022-48303
CVE-2023-23916
=====================================================================
1. Summary:
An update is now available for Red Hat OpenShift GitOps 1.6.
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
2. Description:
Security Fix(es):
* ArgoCD: Authenticated but unauthorized users may enumerate Application
names via the API (CVE-2022-41354)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
3. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
4. Bugs fixed (https://bugzilla.redhat.com/):
2167820 - CVE-2022-41354 ArgoCD: Authenticated but unauthorized users may enumerate Application names via the API
5. References:
https://access.redhat.com/security/cve/CVE-2020-10735
https://access.redhat.com/security/cve/CVE-2021-28861
https://access.redhat.com/security/cve/CVE-2022-1471
https://access.redhat.com/security/cve/CVE-2022-4415
https://access.redhat.com/security/cve/CVE-2022-34174
https://access.redhat.com/security/cve/CVE-2022-40897
https://access.redhat.com/security/cve/CVE-2022-41354
https://access.redhat.com/security/cve/CVE-2022-45061
https://access.redhat.com/security/cve/CVE-2022-48303
https://access.redhat.com/security/cve/CVE-2023-23916
https://access.redhat.com/security/updates/classification/#moderate
6. Contact:
The Red Hat security contact is <secalert at redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBZBzBgdzjgjWX9erEAQhjSBAAh7FvU63tYvcvm9mNr5i4LKeWWbC/otaD
22vtAruUsqWAWLcC2egZMAnYp4lfz0CXyLuz4rQs5rDo5ZCOdREUea57WYrluTkg
cD99cKAiyO30YRkBw8jgtu4ZBOb60tuv+mYWfJzA9/LprYvL+CVgoUaQ1XqviAXq
89dUOSIX1Kc/wMsPkMGzWqiF3c9ai5tCIvW2s9yhFumlFFLdKfvU1ZEoXLGjYs3a
c9CeZlKkhORIQi45197QVDdy/sKW+/aDyojEIUAAw+w8ZHEbNFNQwwwGApHVzOsf
lul6WYoiwwXXBiFMz6fkjo1SmTQIljI2hbW7qphObs8wXDBWzvIuFR3uDEklJMJu
jNuflBhhBso7yx6xRVp/CaTdGr1rR1kNGbqQs3QRlj6KgOsZNaUm86GMF1CoUnFt
0iXMG5gWsn/nJnGor2SgpuJRfMQwjmfp4DO8KIoTWoQ8b7fnLE9jtTerudJiIobk
U5ysjS66ytAqCILyWCvCsJT+L2jLY4oraAyJAyrYVjrIIcHO6T84OnpvqZaZy1ok
Q+I2h9pd5iIjbNWbIJBVje0NUFv/arcTDQDA+PLdZ3V+BK7gisnRHsVHRYUmVGa4
ZNLYDECKEy2CHaSTRlGAwjGoUpO0bZx2uVxyAqoVUDsOUvewgeUP/w7nTdkXX6zh
iFp64IHstt4=
=EYJ/
-----END PGP SIGNATURE-----
More information about the RHSA-announce
mailing list