- Issued:
- 2025-05-28
- Updated:
- 2025-05-28
RHSA-2025:8274 - Important: Errata Advisory for Red Hat OpenShift GitOps v1.14.4 security update
Synopsis
Important: Errata Advisory for Red Hat OpenShift GitOps v1.14.4 security update
Type/Severity
Security Advisory Important
Topic
Errata Advisory for Red Hat OpenShift GitOps v1.14.4 security update.
Description
Errata Advisory for Red Hat OpenShift GitOps v1.14.4 security release.
Security Fix(es):
- openshift-gitops-argocd-container: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS) gitops-1.14
- openshift-gitops-1/gitops-operator-bundle: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS) gitops-1.14
- openshift-gitops-1/argocd-rhel9: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS) gitops-1.14
- openshift-gitops-operator-container: Namespace Isolation Break gitops-1.14
- openshift-gitops-dex-container: Unexpected memory consumption during token parsing in golang.org/x/oauth2 gitops-1.14
- openshift-gitops-container: Potential denial of service in golang.org/x/crypto gitops-1.14
- openshift-gitops-argo-rollouts-container: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS gitops-1.14
- openshift-gitops-argocd-container: jwt-go allows excessive memory allocation during header parsing gitops-1.14
- openshift-gitops-argocd-rhel9-container: jwt-go allows excessive memory allocation during header parsing gitops-1.14
- openshift-gitops-argocd-container: Prototype Pollution in redoc gitops-1.14
- openshift-gitops-argocd-rhel9-container: Prototype Pollution in redoc gitops-1.14
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
Affected Products
| Product | Version | Arch |
|---|---|---|
| Red Hat OpenShift GitOps | 1.14 | x86_64 |
| Red Hat OpenShift GitOps | 1.14 | x86_64 |
| Red Hat OpenShift GitOps for IBM Z and LinuxONE | 1.14 | s390x |
| Red Hat OpenShift GitOps for IBM Power, little endian | 1.14 | ppc64le |
| Red Hat OpenShift GitOps for ARM 64 | 1.14 | aarch64 |
| Red Hat OpenShift GitOps for ARM 64 | 1.14 | aarch64 |
Fixes
CVEs
- CVE-2023-39321
- CVE-2023-39322
- CVE-2023-45288
- CVE-2024-8176
- CVE-2024-9355
- CVE-2024-11187
- CVE-2024-12087
- CVE-2024-12088
- CVE-2024-12133
- CVE-2024-12243
- CVE-2024-12747
- CVE-2024-13484
- CVE-2024-24788
- CVE-2024-24790
- CVE-2024-24791
- CVE-2024-52005
- CVE-2024-56171
- CVE-2024-57083
- CVE-2025-0395
- CVE-2025-22868
- CVE-2025-22869
- CVE-2025-24528
- CVE-2025-24928
- CVE-2025-26465
- CVE-2025-30204
- CVE-2025-47933
References
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.