VDB
RHSA-2025%3A8277
RHSA-2025%3A8277
PUBLISHED
CVSS 8.199999809265137 HIGH
A flaw was found in Argo CD, where improper filtering of repository URLs in the UI allows JavaScript injection. A crafted javascript: link can lead to cross-site scripting when viewed by another user. This can result in unauthorized API actions via the victim's session.
Risk Scores
CVSS 3.1
8.199999809265137
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift-gitops-1/argocd-extensions-rhel8@sha256:f61b8485a0eb8ba0040b8786a5011ca262e23b0c3d2b2392f38ae0cb71b0c565_amd64 as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/argocd-extensions-rhel8@sha256:f61b8485a0eb8ba0040b8786a5011ca262e23b0c3d2b2392f38ae0cb71b0c565_amd64 |
| Red Hat | openshift-gitops-1/gitops-rhel8-operator@sha256:8383e1225608de37e5e58157287d28db6f3931489002c934fabd2283f3d6dff2_s390x as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/gitops-rhel8-operator@sha256:8383e1225608de37e5e58157287d28db6f3931489002c934fabd2283f3d6dff2_s390x |
| Red Hat | openshift-gitops-1/gitops-rhel8-operator@sha256:adb65cb44f6a9bb46f6bd038dd1b6cf282c4fa18cdb9aa3b3967b530fdb80de9_arm64 as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/gitops-rhel8-operator@sha256:adb65cb44f6a9bb46f6bd038dd1b6cf282c4fa18cdb9aa3b3967b530fdb80de9_arm64 |
| Red Hat | openshift-gitops-1/argocd-extensions-rhel8@sha256:b0e9c6058aee36561f551f38244de4877a0aa2a4943364a5c7242e6639200ace_s390x as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/argocd-extensions-rhel8@sha256:b0e9c6058aee36561f551f38244de4877a0aa2a4943364a5c7242e6639200ace_s390x |
| Red Hat | openshift-gitops-1/gitops-rhel8@sha256:c1a3eb6d9d1c25212eaad76c11fd854ab83caa91d6b314123b10137396dff139_ppc64le as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/gitops-rhel8@sha256:c1a3eb6d9d1c25212eaad76c11fd854ab83caa91d6b314123b10137396dff139_ppc64le |
| Red Hat | openshift-gitops-1/gitops-rhel8-operator@sha256:d3ed6273e7fc258bc1d7a11ae1f3a0c01da4f0f8061fac089c14964edc8e8a9d_amd64 as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/gitops-rhel8-operator@sha256:d3ed6273e7fc258bc1d7a11ae1f3a0c01da4f0f8061fac089c14964edc8e8a9d_amd64 |
| Red Hat | openshift-gitops-1/argocd-rhel8@sha256:4266cdf5fdffd689d2454839e4dce7c1074f3e4f1d2d69795fc241117c88da77_ppc64le as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/argocd-rhel8@sha256:4266cdf5fdffd689d2454839e4dce7c1074f3e4f1d2d69795fc241117c88da77_ppc64le |
| Red Hat | openshift-gitops-1/console-plugin-rhel8@sha256:e68c36a3a4d218c3a16ae99ce57fcbf837560a3a9cf2a00e237185be47857fbe_ppc64le as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/console-plugin-rhel8@sha256:e68c36a3a4d218c3a16ae99ce57fcbf837560a3a9cf2a00e237185be47857fbe_ppc64le |
| Red Hat | openshift-gitops-1/argocd-rhel8@sha256:e731d545ad5cb98eb6136de57fce77231ea43a138e8d73f1ad093e59dae2a35d_s390x as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/argocd-rhel8@sha256:e731d545ad5cb98eb6136de57fce77231ea43a138e8d73f1ad093e59dae2a35d_s390x |
| Red Hat | openshift-gitops-1/argocd-rhel9@sha256:217e0384e2bf4547e8ba9e3c41a48a36a56d0c124b9395873df22986baec74b8_arm64 as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/argocd-rhel9@sha256:217e0384e2bf4547e8ba9e3c41a48a36a56d0c124b9395873df22986baec74b8_arm64 |
| Red Hat | openshift-gitops-1/gitops-rhel8@sha256:52b2b85cced911f5b7dd5d34b6f41b19133d90e2fa9a427875f2291d29e4843a_arm64 as a component of Red Hat OpenShift GitOps 1.15 | * |
| Red Hat | openshift-gitops-1/console-plugin-rhel8@sha256:0173916d9d77cfd8f06b1dd08fec157973279b26adc56ab4fc0627bd4484ab2f_s390x as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/console-plugin-rhel8@sha256:0173916d9d77cfd8f06b1dd08fec157973279b26adc56ab4fc0627bd4484ab2f_s390x |
| Red Hat | openshift-gitops-1/gitops-rhel8@sha256:f1b7977f1a32fc101fabb479a44dfedd288c4e9803ec1d6bed3d625251a5f7dc_s390x as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/gitops-rhel8@sha256:f1b7977f1a32fc101fabb479a44dfedd288c4e9803ec1d6bed3d625251a5f7dc_s390x |
| Red Hat | openshift-gitops-1/argocd-rhel8@sha256:043fcda29f079dc74d31260a987b761cc892aa916369f2a13a77592358cc2371_amd64 as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/argocd-rhel8@sha256:043fcda29f079dc74d31260a987b761cc892aa916369f2a13a77592358cc2371_amd64 |
| Red Hat | openshift-gitops-1/dex-rhel8@sha256:0d4cd66b25f856b5891924fd4aafcfd732b671d5e48c11c172c7f87c2fbf1281_amd64 as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/dex-rhel8@sha256:0d4cd66b25f856b5891924fd4aafcfd732b671d5e48c11c172c7f87c2fbf1281_amd64 |
| Red Hat | openshift-gitops-1/argocd-rhel8@sha256:2ae9f86a78aab91d4cc4b90fd1445fe1dccc5832b250c3a3746f5017626d8194_arm64 as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/argocd-rhel8@sha256:2ae9f86a78aab91d4cc4b90fd1445fe1dccc5832b250c3a3746f5017626d8194_arm64 |
| Red Hat | openshift-gitops-1/argo-rollouts-rhel8@sha256:9bcbb795fe718845891db412d5e0a296a74f08ed063e66f6ddca1b128f0e5e8c_ppc64le as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/argo-rollouts-rhel8@sha256:9bcbb795fe718845891db412d5e0a296a74f08ed063e66f6ddca1b128f0e5e8c_ppc64le |
| Red Hat | openshift-gitops-1/dex-rhel8@sha256:e3ac5bbd4d63c914facfcdf302d32b2be0cda4aa617ced830003ddf21923dd1c_s390x as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/dex-rhel8@sha256:e3ac5bbd4d63c914facfcdf302d32b2be0cda4aa617ced830003ddf21923dd1c_s390x |
| Red Hat | openshift-gitops-1/dex-rhel8@sha256:3b3b0c93bbcef63d45169b247a9c3fb2ee6ad88b1dbac4efe0eae19a72aedac1_ppc64le as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/dex-rhel8@sha256:3b3b0c93bbcef63d45169b247a9c3fb2ee6ad88b1dbac4efe0eae19a72aedac1_ppc64le |
| Red Hat | openshift-gitops-1/dex-rhel8@sha256:4a9647a20d639efcfbaf8ed7699d2c1344fc12c99d6947ef3eca8173d97981f8_arm64 as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/dex-rhel8@sha256:4a9647a20d639efcfbaf8ed7699d2c1344fc12c99d6947ef3eca8173d97981f8_arm64 |
…and 15 more
Timeline
- May 28, 2025 CVE Published
- Apr 29, 2026 CVE Updated
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2025:8277 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://issues.redhat.com/browse/GITOPS-5977 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_8277.json advisory
- https://access.redhat.com/security/cve/CVE-2025-47933 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2367740 issue
- https://www.cve.org/CVERecord?id=CVE-2025-47933 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-47933 advisory
- https://github.com/argoproj/argo-cd/security/advisories/GHSA-2hj5-g64g-fp6p advisory