Issued:
2025-05-28
Updated:
2025-05-28

RHSA-2025:8274 - Important: Errata Advisory for Red Hat OpenShift GitOps v1.14.4 security update


Synopsis

Important: Errata Advisory for Red Hat OpenShift GitOps v1.14.4 security update

Type/Severity

Security Advisory Important

Topic

Errata Advisory for Red Hat OpenShift GitOps v1.14.4 security update.

Description

Errata Advisory for Red Hat OpenShift GitOps v1.14.4 security release.

Security Fix(es):

  • openshift-gitops-argocd-container: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS) gitops-1.14
  • openshift-gitops-1/gitops-operator-bundle: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS) gitops-1.14
  • openshift-gitops-1/argocd-rhel9: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS) gitops-1.14
  • openshift-gitops-operator-container: Namespace Isolation Break gitops-1.14
  • openshift-gitops-dex-container: Unexpected memory consumption during token parsing in golang.org/x/oauth2 gitops-1.14
  • openshift-gitops-container: Potential denial of service in golang.org/x/crypto gitops-1.14
  • openshift-gitops-argo-rollouts-container: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS gitops-1.14
  • openshift-gitops-argocd-container: jwt-go allows excessive memory allocation during header parsing gitops-1.14
  • openshift-gitops-argocd-rhel9-container: jwt-go allows excessive memory allocation during header parsing gitops-1.14
  • openshift-gitops-argocd-container: Prototype Pollution in redoc gitops-1.14
  • openshift-gitops-argocd-rhel9-container: Prototype Pollution in redoc gitops-1.14

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

ProductVersionArch
Red Hat OpenShift GitOps1.14x86_64
Red Hat OpenShift GitOps1.14x86_64
Red Hat OpenShift GitOps for IBM Z and LinuxONE1.14s390x
Red Hat OpenShift GitOps for IBM Power, little endian1.14ppc64le
Red Hat OpenShift GitOps for ARM 641.14aarch64
Red Hat OpenShift GitOps for ARM 641.14aarch64

Fixes

CVEs

References


Additional information