Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:9506 - Security Advisory
Issued:
2025-06-24
Updated:
2025-06-24

RHSA-2025:9506 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Red Hat OpenShift GitOps security update

Type/Severity

Security Advisory: Moderate

Topic

Red Hat OpenShift GitOps v1.16.2 release

Description

An update is now available for Red Hat OpenShift GitOps.
Security Fix(es):

  • openshift-gitops-operator-container: Namespace Isolation Break [gitops-1.16](CVE-2024-13484)

Bug Fix(es):

  • Gitops operator is not accepting regular expression in sourceNamespaces - Application in non-controlplane namespaces (GITOPS-6675)
  • gitops-plugin Pods should comply with the Pod Security restricted policy (GITOPS-6777)
  • Missing ArgoCD commit ID in UI (GITOPS-6896)

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258

Fixes

  • https://issues.redhat.com/browse/GITOPS-6675
  • https://issues.redhat.com/browse/GITOPS-7037
  • https://issues.redhat.com/browse/GITOPS-6777
  • https://issues.redhat.com/browse/GITOPS-6896

CVEs

  • CVE-2024-13484

References

  • https://access.redhat.com/security/cve/cve-2024-13484
  • https://access.redhat.com/security/updates/classification/
  • https://docs.redhat.com/en/documentation/red_hat_openshift_gitops/1.16/

amd64

registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:66a05dbe2c838e38fd4ba7634f3e2687017dc75acf1226e16c7046697c2ec6a6
registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:b2d3757f0de603eb0f39f821642b27b915b1317b0d02513cc112d15531d53a1b
registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:28a3ed9273aa1cbf66f002dea963f45165f3675e7cced6d0267aafed75256e1c
registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:0043c38927694097d753d20ed189a7fbaf331dc3cf631465bb3a5973fdb4844c
registry.redhat.io/openshift-gitops-1/gitops-rhel8@sha256:4d4fd5ad560ee73533587642ab7fc2838a400288433b697eee312c81c498658a
registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:b33ca45c04bb1fa7e72ad66da8839305e6ed24dedeaa04b64c5bc393bf7af397
registry.redhat.io/openshift-gitops-1/must-gather-rhel8@sha256:d5e31695ac2b9a5fcee8f56c41d44884e9464f5cad29d8a8d050a8dbe2b78143
registry.redhat.io/openshift-gitops-1/gitops-rhel8-operator@sha256:fcc25f81533e0485dd626ce8ef573caafb5d8944e061ee8541f22aa34e066338
registry.redhat.io/openshift-gitops-1/gitops-operator-bundle@sha256:cc14268ddbd89c654124439711249fc888a50de97ddf0e29d9665cd490bb1aeb

arm64

registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:6b46a60526a6ca7b112d6e031b05a68f51b088979eab950d6307a82b93789775
registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:32af5cafad41025ed016ce016d4b71346c79cc59af9f861ce3e4d6c763b62616
registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:98ba4a0e9b1946b09159b591cef4f0afe85b0c5d692892b7b8c7979422bf8cbe
registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:e1e028561be60a45b36388c94532e192d7a684087ba0224195e35ab1f209802f
registry.redhat.io/openshift-gitops-1/gitops-rhel8@sha256:1e74ebf5fd6ba3af207f6176550074b2958ff073174f4e0db046ede32403dba5
registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:a1037e89f690785b715fb0e3e16f63761c6aba294a430c78ac91f373f1c8aadb
registry.redhat.io/openshift-gitops-1/must-gather-rhel8@sha256:de09ec72794b71919ff9ffd1669b5e53107885bbac4709861a209312a09b946c
registry.redhat.io/openshift-gitops-1/gitops-rhel8-operator@sha256:4c56abf35c11af85501a8c4a2ec30b1f1efd28eee8af6d62e417846a40cde72e

ppc64le

registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:38bb3c35d6b1a6acc1b5b1fac2d3fbb1d7666d541c1aafa67ce72a2582613101
registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:8959ae3709067b7cd6e389a6c70d0d09b890007f7f2cd65b4a2bfc22b4f97a2d
registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:bb8d712ae51005be2cca0a98111e5798550226e5b2a34befe7f012417e772a65
registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:b32703b7ffe202a315fe9b583fc84b94ae4a12a7cbcbd90c034e5ca07e3df64b
registry.redhat.io/openshift-gitops-1/gitops-rhel8@sha256:8ff92f79f5120140e0aa9ceb197661fd170ee7c68f99637251731435313ab04a
registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:c26c7b47feb5144d686a23da871f5b762f07c08f0207824f91e8b7f171004f6a
registry.redhat.io/openshift-gitops-1/must-gather-rhel8@sha256:7e44683bc8b54e91051a627d413ac8ef51ed00080cec577bd5191bc59e50ee87
registry.redhat.io/openshift-gitops-1/gitops-rhel8-operator@sha256:81ea9837bfd653a2e965e7d545afede7d4bee6bf9cc658b7c81aceb6ee097b05

s390x

registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:529cfb5c13b9c5724c69f201639fe31f28b98df411ea0d4c7d2a6dc71d75b710
registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:2f6af92a47b24f9f9ac214d5961c8a4cdf3f458ddf5fd9588be5ed9295ad4557
registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:a083c8ad66fe69f7fa59c1002ee8cb477286eb14576bb1b034be4a9b8c13853e
registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:bc9bd4c8d18e5c2066aff0ec3e96ab0f540e31130e7e0db40236e2bfdd239ae0
registry.redhat.io/openshift-gitops-1/gitops-rhel8@sha256:6555c3c45e0b61deb7ef6e8100eca1764731316592637fcdbe867bf3636cd78f
registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:aed68357134c7b7b832f36d150b89c50bbac05f3f60d4d7faf24a641b9869991
registry.redhat.io/openshift-gitops-1/must-gather-rhel8@sha256:4b388c6a523ef995849010f8f2dea4ea95e3814279f1add58bcd0f855e4586c2
registry.redhat.io/openshift-gitops-1/gitops-rhel8-operator@sha256:62d0a872cc40558260a4fc4cc55c39b9e0ef6d495f798b8ff0e10161f555a003

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility