drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Zwei Probleme in Red Hat OpenShift GitOps
| Name: |
Zwei Probleme in Red Hat OpenShift GitOps |
|
| ID: |
RHSA-2025:1888 |
|
| Distribution: |
Red Hat |
|
| Plattformen: |
Red Hat OpenShift GitOps 1.15 |
|
| Datum: |
Do, 27. Februar 2025, 07:00 |
|
| Referenzen: |
https://bugzilla.redhat.com/show_bug.cgi?id=2335901
https://issues.redhat.com/browse/GITOPS-5970
https://issues.redhat.com/browse/GITOPS-6032
https://access.redhat.com/security/cve/CVE-2025-21614
https://issues.redhat.com/browse/GITOPS-6288
https://issues.redhat.com/browse/GITOPS-5978
https://access.redhat.com/security/cve/CVE-2025-23216
https://access.redhat.com/errata/RHSA-2025:1888
https://issues.redhat.com/browse/GITOPS-5967 |
|
| Applikationen: |
Red Hat OpenShift GitOps |
|
Originalnachricht |
An update is now available for Red Hat OpenShift GitOps v1.15.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Errata Advisory for Red Hat OpenShift GitOps v1.15.1.
Security Fix(es):
* openshift-gitops-argocd-rhel9-container: go-git clients vulnerable to DoS via maliciously crafted Git server replies [gitops-1.15](CVE-2025-21614) * openshift-gitops-argocd-container: go-git clients vulnerable to DoS via maliciously crafted Git server replies [gitops-1.15](CVE-2025-21614) * openshift-gitops-container: go-git clients vulnerable to DoS via maliciously crafted Git server replies [gitops-1.15](CVE-2025-21614) * openshift-gitops-argocd-rhel9-container: Argo CD does not scrub secret values from patch errors [gitops-1.15](CVE-2025-23216) * openshift-gitops-container: Argo CD does not scrub secret values from patch errors [gitops-1.15](CVE-2025-23216) * openshift-gitops-operator-bundle-container: Argo CD does not scrub secret values from patch errors [gitops-1.15](CVE-2025-23216) * openshift-gitops-operator-container: Argo CD does not scrub secret values from patch errors [gitops-1.15](CVE-2025-23216)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.
CVE-2025-21614: Allocation of Resources Without Limits or Throttling (CWE-770) CVE-2025-23216: Generation of Error Message Containing Sensitive Information (CWE-209)
|
|
|
|