-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat OpenShift GitOps security update Advisory ID: RHSA-2022:0477-01 Product: Red Hat OpenShift GitOps Advisory URL: https://access.redhat.com/errata/RHSA-2022:0477 Issue date: 2022-02-08 CVE Names: CVE-2021-3521 CVE-2022-24348 ==================================================================== 1. Summary: An update is now available for Red Hat OpenShift GitOps 1.4 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat Openshift GitOps is a declarative way to implement continuous deployment for cloud native applications. Security Fix(es): * gitops: Path traversal and dereference of symlinks when passing Helm value files (CVE-2022-24348) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2050826 - CVE-2022-24348 gitops: Path traversal and dereference of symlinks when passing Helm value files 5. JIRA issues fixed (https://issues.jboss.org/): GITOPS-1751 - route.openshift.io/v1 resource Health stuck in "Progressing" with details "Route is still getting admitted 6. References: https://access.redhat.com/security/cve/CVE-2021-3521 https://access.redhat.com/security/cve/CVE-2022-24348 https://access.redhat.com/security/updates/classification/#important 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYgNt3tzjgjWX9erEAQgOOhAAicf4ZrNT+M+7D4MODcO3Fh2HGg+JyXHI 2Duid6hBQoIlOvrKYomXUhwV+NFM3sTVNC3lOdF1bjwpBVYEScI3Gfu9IlYApAww QXk1wBUpcr2NEt/TzBu1gmjvQxIgIkpZjl8Q/7GNCWA2OS2VdKhSTDrREihDZYXK oSipu4gzYsWpRc8ED/RMR0Z1D+lxncczVkBEYiAfAOGVOVwCV89WVr8ROPr02fHq 8ypg50gHdAe3pPOd9fWun/ZxPYdOiKNNtwslE0QeTqA6s9JnBvwiowDhyaYfuZr6 bYTxkeGjfude09AUKbzK5v3A1wDJf6QbWnNC3QW6e+0q293pSGIg4DZemX0a2LKY ppxw4xaaBvBFaVd/nTBqoUOE3vDgKNGfUBEHyLV3NM2qyl7Pt39Cg3+RQgx86rFb IXm257Ee6G5S0iSKXwjPisegVKs0H7uNeeN6N441CGjT/58UZx1G+HGj5Lu5fNPL w15u75C+sNhOxMdgKCeM1c/TFzCln/1eZnOtqwD2ObKrkze6ZvTwvJvl4f9WLaJY JMcieYztE+9bNk7C5YqmxChvE2xw2IiLnsFNPu0tCqxJYDBVX1z8751n0CloEOm3 lJemiE2LyWaT4l7HAoKGnuX0maoiLEznowkbgHS0bMaPi5cUhzFSt0u6aAtl3M01 aBgt7uwDE30=ZYYw -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce