Description

A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can have adverse effects on the platform monitoring stack, as the rule is rolled out cluster-wide when the label is applied.

INFO

Published Date :

2025-01-28T17:54:28.701Z

Last Modified :

2026-02-25T18:24:30.362Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2024-13484 vulnerability.

Vendors Products
Redhat
  • Openshift Gitops

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact