RHSA-2024:1697HighCVSS 7.5
Red Hat Security Advisory: Errata Advisory for Red Hat OpenShift GitOps v1.11.3 security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2023-50726 — CD: Users with create but not override privileges can perform local sync
CVE-2024-21652 — argo-cd: Bypassing Brute Force Protection via Application Crash and In-Memory Data Loss
CVE-2024-21661 — argo-cd: Denial of Service Due to Unsafe Array Modification in Multi-threaded Environment
CVE-2024-21662 — argo-cd: Bypassing Rate Limit and Brute Force Protection Using Cache Overflow
CVE-2024-29893 — argo-cd: uncontrolled memory allocation vulnerability
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2024:1697
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.openshift.com/gitops/1.11/release_notes/gitops-release-notes.html
- externalhttps://docs.openshift.com/gitops/1.11/understanding_openshift_gitops/about-redhat-openshift-gitops.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2269479
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270170
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270173
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270182
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2272211
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1697.json