Bug 2162517 (CVE-2023-22736)
| Summary: | CVE-2023-22736 argocd: Controller reconciles apps outside configured namespaces when sharding is enabled | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Zack Miele <zmiele> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | ellin, rgarg, scorneli, security-response-team, shbose, ubhargav |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | ArgoCD-2.6.0-rc5, ArgoCD-2.5.8, ArgoCD-2.4.20, ArgoCD-2.3.14 | Doc Type: | If docs needed, set a value |
| Doc Text: |
A flaw was found in Red Hat GitOps, which is vulnerable to an authorization bypass in ArgoCD. This flaw allows users to deploy applications outside the allowed namespaces. The issue happens due to a logic error when interpreting the comma-separated namespaces list. To complete the attack, the attacker must have enough privileges to update deployed applications.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2023-01-28 05:22:10 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 2162518 | ||
|
Description
Zack Miele
2023-01-19 19:00:48 UTC
This issue has been addressed in the following products: Red Hat OpenShift GitOps 1.7 Via RHSA-2023:0467 https://access.redhat.com/errata/RHSA-2023:0467 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2023-22736 |