(RHSA-2022:4691) Important: Red Hat OpenShift GitOps security update
Discription
Red Hat Openshift GitOps is a declarative way to implement continuous deployment for cloud native applications.
Security Fix(es):
* argocd: ArgoCD will blindly trust JWT claims if anonymous access is enabled (CVE-2022-29165)
* argocd: Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server (CVE-2022-24904)
* argocd: Login screen allows message spoofing if SSO is enabled (CVE-2022-24905)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Read More
References
Back to Main