Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:1454 - Security Advisory
Issued:
2023-03-23
Updated:
2023-03-23

RHSA-2023:1454 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: Red Hat OpenShift GitOps security update

Type/Severity

Security Advisory: Moderate

Topic

An update is now available for Red Hat OpenShift GitOps 1.7.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Security Fix(es):

  • ArgoCD: Authenticated but unauthorized users may enumerate Application names via the API (CVE-2022-41354)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift GitOps 1.7 x86_64
  • Red Hat OpenShift GitOps for IBM Power, little endian 1.7 ppc64le
  • Red Hat OpenShift GitOps for IBM Z and LinuxONE 1.7 s390x

Fixes

  • BZ - 2167820 - CVE-2022-41354 ArgoCD: Authenticated but unauthorized users may enumerate Application names via the API

CVEs

  • CVE-2020-10735
  • CVE-2021-28861
  • CVE-2022-1471
  • CVE-2022-4415
  • CVE-2022-34174
  • CVE-2022-40897
  • CVE-2022-41354
  • CVE-2022-45061
  • CVE-2022-48303
  • CVE-2023-23916

References

  • https://access.redhat.com/security/updates/classification/#moderate

ppc64le

openshift-gitops-1/argocd-rhel8@sha256:60f0991fb9cdce298e39a9daa29b353d34b83dd70200a70e21c66bf0e140d94b
openshift-gitops-1/console-plugin-rhel8@sha256:95e331ef0ea455a93fd448319d639cbce39dccbe38eb7ccf9def9b2bba0e7c99
openshift-gitops-1/dex-rhel8@sha256:739fa286d530b9a1d01b9a62fabe4d8d36c0eff7069af126e011c8e83f33020f
openshift-gitops-1/gitops-rhel8@sha256:f7df393bc26c4e77ffc24aba3c428e507d88d8bfee3de46f3cc8854d75270341
openshift-gitops-1/gitops-rhel8-operator@sha256:a7e5bce60edf1309c5aa142c53f67594803bb4f4734b984824e9bcfe9b826baa
openshift-gitops-1/kam-delivery-rhel8@sha256:4cb28da91b432eef9bc8bd649c48fac70a56b4ccef0a2b8f9a7dc6d8c8e70ee2

s390x

openshift-gitops-1/argocd-rhel8@sha256:830d3e65e506947d6558c61b34205b636fdc15d19b460c18170f441a8ac326e4
openshift-gitops-1/console-plugin-rhel8@sha256:e4aca4f654d1239bb101bbf1ba5b9e1f52721843c075430e9893c38112a25c4a
openshift-gitops-1/dex-rhel8@sha256:2c18b70417c2e53bfb893686b9c2a4c1eec3b5f38db9c9cf0749e0535edad080
openshift-gitops-1/gitops-rhel8@sha256:76830d53754637826b20840adc3183c4edc9387d669e8035fc39966c79e961c5
openshift-gitops-1/gitops-rhel8-operator@sha256:3569e06d18396f89aeb55c84e93af06183358d18867d8e6d238dfa168e498920
openshift-gitops-1/kam-delivery-rhel8@sha256:d7575bf9fc7b563022bd31c469850838e686306c1fd9f8975a1d975d76b30779

x86_64

openshift-gitops-1/argocd-rhel8@sha256:aa77a8f11bf0b4358ba0b71cfc149235987c2e669e13e7fa0297216b78909600
openshift-gitops-1/console-plugin-rhel8@sha256:9f5e8ccea8fe89d003abe3e7884efb05521bff8abe55d69ca45477060f29995e
openshift-gitops-1/dex-rhel8@sha256:ddaea14fc0b9f21524359fcd00c0e682721ce40c33b31a8ef3c1553aef295134
openshift-gitops-1/gitops-operator-bundle@sha256:b4a5bccf0a2d03ee1164e67e508a23fb26ac3f39433514d83807b1a4e5d32219
openshift-gitops-1/gitops-rhel8@sha256:c2135416f1fd7ee7e9f3603f9e5d4401b6f7ba5d5d3f1b0208016d38888ffdd3
openshift-gitops-1/gitops-rhel8-operator@sha256:b0cc1ff4ace50d2e8cf408f4daa7922c85a6a052a9034e68546beb7391967fce
openshift-gitops-1/kam-delivery-rhel8@sha256:e99b94f31fe1bbaf56764acdf4428cec3cf48a144519e5a3e141c923902d201f

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility