RHSA-2024:0692CriticalCVSS 8.3
Red Hat Security Advisory: Errata Advisory for Red Hat OpenShift GitOps 1.10.2 security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2023-49568 — go-git: Maliciously crafted Git server replies can cause DoS on go-git clients CVE-2023-49569 — go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients CVE-2024-22424 — argo-cd: vulnerable to a cross-server request forgery (CSRF) attack
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2024:0692
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://docs.openshift.com/gitops/1.10/understanding_openshift_gitops/about-redhat-openshift-gitops.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258143
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258165
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2259105
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0692.json