Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:8677 - Security Advisory
Issued:
2024-10-30
Updated:
2024-10-30

RHSA-2024:8677 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: Errata Advisory for Red Hat OpenShift GitOps v1.12.6 security update

Type/Severity

Security Advisory: Important

Topic

An update is now available for Red Hat OpenShift GitOps v1.12.6. Red Hat
Product Security has rated this update as having a security impact of Important.
A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Errata Advisory for Red Hat OpenShift GitOps v1.12.6.

Security Fix(es):

  • openshift-gitops-argocd-container: openshift-gitops-argocd-container: Denial of Service Vulnerability in body-parser [gitops-1.12](CVE-2024-45590)
  • openshift-gitops-console-plugin-container: follow-redirects: Possible credential leak [gitops-1.12](CVE-2024-28849)
  • openshift-gitops-dex-container: golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON [gitops-1.12](CVE-2024-24786)
  • openshift-gitops-argocd-container: go-retryablehttp: url might write sensitive information to log file [gitops-1.12](CVE-2024-6104)
  • openshift-gitops-argocd-container: Improper Sanitization in serve-static [gitops-1.12](CVE-2024-43800)
  • openshift-gitops-argocd-container: Improper Input Handling in Express Redirects [gitops-1.12](CVE-2024-43796)
  • openshift-gitops-argocd-container: Code Execution Vulnerability in Send Library [gitops-1.12](CVE-2024-43799)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift GitOps 1.12 for RHEL 9 x86_64
  • Red Hat OpenShift GitOps 1.12 for RHEL 8 x86_64
  • Red Hat OpenShift GitOps for IBM Power, little endian 1.12 ppc64le
  • Red Hat OpenShift GitOps for IBM Z and LinuxONE 1.12 s390x
  • Red Hat OpenShift GitOps for ARM 64 1.12 for RHEL 9 aarch64
  • Red Hat OpenShift GitOps for ARM 64 1.12 for RHEL 8 aarch64

Fixes

  • GITOPS-4234 - Dynamic Plugin loading very slowly

CVEs

  • CVE-2023-37920
  • CVE-2024-1737
  • CVE-2024-1975
  • CVE-2024-2398
  • CVE-2024-4032
  • CVE-2024-5535
  • CVE-2024-6104
  • CVE-2024-6232
  • CVE-2024-6345
  • CVE-2024-6923
  • CVE-2024-24786
  • CVE-2024-28849
  • CVE-2024-30203
  • CVE-2024-30205
  • CVE-2024-34156
  • CVE-2024-37370
  • CVE-2024-37371
  • CVE-2024-37891
  • CVE-2024-38428
  • CVE-2024-39331
  • CVE-2024-43796
  • CVE-2024-43799
  • CVE-2024-43800
  • CVE-2024-45490
  • CVE-2024-45491
  • CVE-2024-45492
  • CVE-2024-45590

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

openshift-gitops-1/argo-rollouts-rhel8@sha256:600239219d6abc36e239c4378f1a5ae6360bfe6367c5bbbacaf713d4194cb066
openshift-gitops-1/argocd-rhel8@sha256:ef1882372a4a0c12604c544aa09ebc0fb6697f2108accd74f423e8a42a9a849a
openshift-gitops-1/argocd-rhel9@sha256:620040787b5e670a227bf57cc25166c931cfe0cfbf6352ac56cacfbd97eca142
openshift-gitops-1/console-plugin-rhel8@sha256:b7e59715fc4ddc0d6cc70ec0eb14660fa25d1a10d784fa7d39e26ea657d90ca2
openshift-gitops-1/dex-rhel8@sha256:278f783a708bf4f0984c525d8faac82642519322e0ed74c4facc10db42578a85
openshift-gitops-1/gitops-rhel8@sha256:7135ff9064edcdc78f941ee6440f611bbee2cdd9fcdcab304eb12d4be043e8ef
openshift-gitops-1/gitops-rhel8-operator@sha256:7419af667f37858951d00f889d7972f07a2bbce506371369b2bbc3d85afbe568
openshift-gitops-1/kam-delivery-rhel8@sha256:8ab3edc2f56d6b195ac31865c21dbad4834c08d2aa5f7d111cfc0f57c3f0ce76
openshift-gitops-1/must-gather-rhel8@sha256:fbd2311d841e9ce89c63c8959c4ba296075fa33ed0a75d3e169d6e7d0162f226

ppc64le

openshift-gitops-1/argo-rollouts-rhel8@sha256:42d01565f1c8b85e5dc480b34aea52fdce15a7071c65102b73bc45864f30217c
openshift-gitops-1/argocd-rhel8@sha256:df9455d9cb06511fd94a7335fd256d31a16cfdefc7af1431b0693de53811eb61
openshift-gitops-1/console-plugin-rhel8@sha256:49299450da07c7d63cd34104182634b267903ce4c86a9598fc1da72073ef885c
openshift-gitops-1/dex-rhel8@sha256:b41b9d088cb71cbf9a57c8fd63a52462ffa9dbd0ac1cb6358c688a45035ca3c5
openshift-gitops-1/gitops-rhel8@sha256:d2d712ddc8daeb9293080848ccbc4e368bbb8732caabaebdba61839a6f34cb85
openshift-gitops-1/gitops-rhel8-operator@sha256:6f1b7e9b88c56ac34029eb18148828485b88abbc291a0f36095d585792fa5b9b
openshift-gitops-1/kam-delivery-rhel8@sha256:9a91b3b11c52ff74cf47fe1ab3f21d0f9c0ccfe2b1d8a0e42e383286c3a185e2
openshift-gitops-1/must-gather-rhel8@sha256:6f13f8c8e710641972c410c0400e64447fb529fb4038a85d59a00d0893448e73

s390x

openshift-gitops-1/argo-rollouts-rhel8@sha256:30de68a0ecca94c6cbf06d0f7bbd91651bc3733a6ee496b58cdcc5c6d1b7fe84
openshift-gitops-1/argocd-rhel8@sha256:3b4a0a076a0954e4bf45898872a4db41a45d6f4223b097931fb3458c72e0e287
openshift-gitops-1/console-plugin-rhel8@sha256:e7e12eab0e329bbc4ba85ae71508c667e13a6f707806ab938e78bb4d05377377
openshift-gitops-1/dex-rhel8@sha256:c49f49e26ba3c155f3e78e1444d4fa400415d5517bad654eed1a59437311fe40
openshift-gitops-1/gitops-rhel8@sha256:c4935ae04342535d4ff8f1e7d4b63b3a7b9d675a4a65852784ebc680229c0b8e
openshift-gitops-1/gitops-rhel8-operator@sha256:1da6cc56730caf7dce6039bff116137023ef6fd28a7a9ead31f3aa44da336461
openshift-gitops-1/kam-delivery-rhel8@sha256:1b0572536b919548af38ad77f348b341f1a8052812528ab309ac9c4e623655cb
openshift-gitops-1/must-gather-rhel8@sha256:b3887fd6109bc55507b134e9ebd596a89d42413ccb5b863f328c60bd1b668afd

x86_64

openshift-gitops-1/argo-rollouts-rhel8@sha256:8405b9602109392ae984137d143f91b8f2b7550d5fca16902b1b38ad62117072
openshift-gitops-1/argocd-rhel8@sha256:b5ecdbfb2000470a8efa46e6cb62c850db7c4acebd46b11d7c791c98b445ca44
openshift-gitops-1/argocd-rhel9@sha256:3dfa640a19aaaa00062e1b13347f28f070447cf4e41445f3bcc520537be43ba6
openshift-gitops-1/console-plugin-rhel8@sha256:e4fac9da180ce7fcb2cd24d7c5ed54847fdca24c783e6866a4917307a791a92a
openshift-gitops-1/dex-rhel8@sha256:383d9b606fe190b15b570949c34ce8109bfced4274e9f1edd339266bdc4cad96
openshift-gitops-1/gitops-operator-bundle@sha256:80198f65f7e3f9022a34e0342e9423807b855dcb7bda810172eebc9a27afb5c2
openshift-gitops-1/gitops-rhel8@sha256:d9faecc2318952cab075b57006c862fe8cbcc869efb18d45aa29a08fc24e7479
openshift-gitops-1/gitops-rhel8-operator@sha256:70d1de694942fae82528179affc9408abfa835c5c14a438b13953f7300267d66
openshift-gitops-1/kam-delivery-rhel8@sha256:edf99302ddb3cb16d27f575929b5a59b22f50ff605eceaa6e29f1be72b02bc5c
openshift-gitops-1/must-gather-rhel8@sha256:f0eaf113b4a3aec59bd5144af00d807391c33e410e56e05175c0685fd672305b

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility