- Issued:
- 2025-05-28
- Updated:
- 2025-05-28
RHSA-2025:8269 - Important: Red Hat OpenShift GitOps 1.16.1 security release
Synopsis
Important: Red Hat OpenShift GitOps 1.16.1 security release
Type/Severity
Security Advisory Important
Topic
Errata advisory for Red Hat OpenShift GitOps 1.16.1 security release.
Description
The Red Hat OpenShift GitOps 1.16.1 release provides security updates to the Argo CD CLI, Argo Rollouts CLI and MicroShift GitOps.
Security Fix(es):
- openshift-gitops-1/argocd-rhel9: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS) gitops-1.16
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
Affected Products
| Product | Version | Arch |
|---|---|---|
| Red Hat OpenShift GitOps | 1.16 | x86_64 |
| Red Hat OpenShift GitOps | 1.16 | x86_64 |
| Red Hat OpenShift GitOps for IBM Z and LinuxONE | 1.16 | s390x |
| Red Hat OpenShift GitOps for IBM Power, little endian | 1.16 | ppc64le |
| Red Hat OpenShift GitOps for ARM 64 | 1.16 | aarch64 |
| Red Hat OpenShift GitOps for ARM 64 | 1.16 | aarch64 |
Updated Packages
- openshift-gitops-argocd-cli-1.16.1-10.el9.aarch64.rpm
- openshift-gitops-argocd-cli-1.16.1-26.el8.s390x.rpm
- openshift-gitops-argocd-cli-redistributable-1.16.1-26.el8.x86_64.rpm
- openshift-gitops-argocd-cli-redistributable-1.16.1-10.el9.x86_64.rpm
- openshift-gitops-argocd-cli-1.16.1-26.el8.aarch64.rpm
- microshift-gitops-1.16.1-10.el9.aarch64.rpm
- openshift-gitops-argocd-cli-1.16.1-26.el8.ppc64le.rpm
- microshift-gitops-release-info-1.16.1-10.el9.noarch.rpm
- microshift-gitops-1.16.1-10.el9.x86_64.rpm
- openshift-gitops-argocd-cli-1.16.1-10.el9.src.rpm
- openshift-gitops-argocd-cli-1.16.1-26.el8.src.rpm
- openshift-gitops-argocd-cli-1.16.1-26.el8.x86_64.rpm
- microshift-gitops-1.16.1-10.el9.src.rpm
- openshift-gitops-argocd-cli-1.16.1-10.el9.x86_64.rpm
Fixes
CVEs
References
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.