- Issued:
- 2025-12-15
- Updated:
- 2025-12-15
RHSA-2025:23207 - Security Advisory
Synopsis
Important: Red Hat OpenShift GitOps v1.16.5 security update
Type/Severity
Security Advisory: Important
Topic
Important: Red Hat OpenShift GitOps v1.16.5 security update
Description
An update is now available for Red Hat OpenShift GitOps.
Bug Fix(es) and Enhancement(s):
- GITOPS-8116 (CVE-2024-45338 openshift-gitops-dex-container: Non-linear parsing of case-insensitive content in golang.org/x/net/html [gitops-1.17])
- GITOPS-8019 (CVE-2025-49844 - Vulnerability with Redis)
- GITOPS-8142 (CVE-2024-45337 reported by RHACS for OpenShift GitOps Operator v1.18.1 (ArgoCD-based) due to outdated git-lfs binary, dependency update required to remove false positive.)
- *Post-Upgrade Action Required: Audit GitOps Operator Roles**
Following this upgrade, we strongly recommend you run the provided audit script to review namespace-scoped access.
- The script identifies Roles/RoleBindings that grant cross-namespace access for the GitOps operator's features (created via .spec.sourceNamespaces).
- Run it to verify and confirm that only the intended namespaces have cross-namespace access to deploy applications.
For more details, refer to :
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
amd64
| registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:d22dd4dd09ac5762db0e1640b0f4e095d9d7d8ab2a4a19a6387b1c677cc299bb |
| registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:be490bdfd6f793e7298e13792ee230cf6f061a67727aac6a0a6f298e02d106ce |
| registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:5083f82c8c279384a9b1ffb03295da165d5b2e7c12538f5792b094830d8628bc |
| registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:529989e5fb64e6451ae21dd10f293e182ae52a3f938abe6e8082cf415cb0fb35 |
| registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:f4c13bc089a23eb0ce2057a9bc7f6ae7ea626b9ef27a568410f2e94fe27d6c07 |
| registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:f0c88a955a27b9939c7be9304ba56ea794cf08c4c2e9637eb7f06fb59055d416 |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8@sha256:8ea5487a8a33b44fd6b7d3b2749dc46bc39b72dce1725cf3c612be78669c43cc |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8-operator@sha256:bcc192e3e9ff8dfd15bd311fdeda919653721e85338c96d5ad29fa6f1e4e3365 |
| registry.redhat.io/openshift-gitops-1/gitops-operator-bundle@sha256:1e7fb9262023798711dc58fecf9c57c2fbd260a7f942eef2a9fd2822dbfb0b74 |
| registry.redhat.io/openshift-gitops-1/must-gather-rhel8@sha256:632e6c439c879fdc116d9ba28c46d8b703a82c7e74e2ea6d609ebb0f33d5b58c |
arm64
| registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:9330fc60983057b6e4d5982a9d26f75edd19f60a27e51d399d432904fd6fabeb |
| registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:79b152b79000b6a9673f62bdaf0bf7ddd9175483cc8e3732417738569d9dcba3 |
| registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:b560d638da1fd627ffe238a770d2b0a382f9947b429a02c22a39cfec7a9a14bd |
| registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:990d911c2141f78e8f2bae55f7de8b400d0e02dec1ea761d2befe24954debe88 |
| registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:01a290257f7a67491567952e14fe172486de00dec8bf7c963482bea6d4b3f9c7 |
| registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:86b9fb43226ae1b8db105c67f882388aaf4f6df816e3d90e5be1de234b48ad4d |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8@sha256:50c6fdcaa62c5eb09dad85edbfb3e0818870c1d0ae6121c328375826e727a2f2 |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8-operator@sha256:52b550b043480277626e591ec85b832e91f69b5f91dd72fc8823788635f0eb11 |
| registry.redhat.io/openshift-gitops-1/must-gather-rhel8@sha256:6564195bb96a655e4951e9ed310f18dd328045704f40b5834317fb4a1fd42471 |
ppc64le
| registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:9612285bdfdef053b85e20ae1f051fa920e54dab0fb2fe2eb07361a9b4a11b5b |
| registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:128bc4204874b52f3d92a363224cf111b9d3905402526fe3cc267a52679bff2d |
| registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:ca1bb876d3e7b3dfede5b542a7c6a8bdece5555cc872f97d7e7a31823dad2fd5 |
| registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:60be065c239e044ae5f9ac38a20d5d76e9f1912c2fa2bd84f7f0d0697a1e6cda |
| registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:206ef103465edbeef20de28b0c936eb1aa8403100f5ee58984964d614d099ea6 |
| registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:28291a0151e5c5acc71c0da1dcf6d0476280bb12c81483c8c5f09929844ba0eb |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8@sha256:d84b86fdba90d33ea4486833a22c277143ef74a61bfcfa18f3a77657ddd92a2c |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8-operator@sha256:c41c99f360a2515bce55c42e309e2c72500ba66d3a2c461412dee7de5ea9a9fa |
| registry.redhat.io/openshift-gitops-1/must-gather-rhel8@sha256:04167997bbf8fc40e6010c9eb0510bcdadaabb00037c36ed95ae990a78032691 |
s390x
| registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:1b6aa315db581860193221a3f9c6fc41aee27e565be3b35d3bcfdf96b78aa9a1 |
| registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:0c5deccc37d4904c3d9e2395f8633588ab9ea2516f2b64809ff27eae06c0a4cb |
| registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:22d449937c066aea055b8591723934174748907161e4ff9f9086b59c5e95bf4f |
| registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:603bef1d5ab79b33458edc81bf06d32dd5be50df06eab25a0a1973c9083d7553 |
| registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:b4fac7c2dbc1139f070ab594e35bd2f424b81a4fa025754d1b3a7a4864c3a6c5 |
| registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:d30ca5a1264146a12fe1f86f669272585a8976cbe2facba5c75fe1bf5ad46d26 |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8@sha256:50f449a62b01b2c068b6d0cb4afe822a9c16256da520dc3d447a279ac3f80fe9 |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8-operator@sha256:d6102d2d2c0f46d8ceb81d7d85dba857283a6bca3828a99ccaef9feec7c1478a |
| registry.redhat.io/openshift-gitops-1/must-gather-rhel8@sha256:3b09515064d1552e910a52fce75cf23774776747855a281bb03c67617924fe3f |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.