<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Argo CD (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/argo-cd.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/argo-cd-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Argo CD (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:51 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-42880 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42880</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42880</guid>
    <pubDate>Thu, 07 May 2026 23:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42880</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism. T…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42880">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43824 – In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows rea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43824</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43824</guid>
    <pubDate>Sat, 02 May 2026 02:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43824</strong></p>
  <p>In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-212</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43824">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6388 – A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6388</guid>
    <pubDate>Wed, 15 Apr 2026 22:17:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6388</strong></p>
  <p>A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a multi-tenant environment, to bypass namespace boundaries. By exploiting insufficient validation, the attacker can trigger unauthorized image updates on applications managed by other tenants. This leads to cross-namespace privilege escalation, impactin…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-1220</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24748 – Kargo manages and automates the promotion of software artifacts. Prior to versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24748</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24748</guid>
    <pubDate>Tue, 27 Jan 2026 22:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24748</strong></p>
  <p>Kargo manages and automates the promotion of software artifacts. Prior to versions 1.8.7, 1.7.7, and 1.6.3, a bug was found with authentication checks on the `GetConfig()` API endpoint. This allowed unauthenticated users to access this endpoint by specifying an `Authorization` header with any non-empty `Bearer` token value, regardless of validity.  This vulnerability did allow for exfiltration of…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24748">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-13888 – A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13888</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13888</guid>
    <pubDate>Mon, 15 Dec 2025 16:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-13888</strong></p>
  <p>A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated permissions in other namespaces, including privileged namespaces. An authenticated attacker can then use these elevated permissions to create privileged workloads that run on master nodes, effectively giving them root access to the entire cluster.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13888">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59538 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. For ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59538</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59538</guid>
    <pubDate>Wed, 01 Oct 2025 21:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59538</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. For versions 2.9.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.6 and 3.0.17, when the webhook.azuredevops.username and webhook.azuredevops.password are not set in the default configuration, the /api/webhook endpoint crashes the entire argocd-server process when it receives an Azure DevOps Push event whose JSON arr…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59538">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59537 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59537</guid>
    <pubDate>Wed, 01 Oct 2025 21:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59537</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 are vulnerable to malicious API requests which can crash the API server and cause denial of service to legitimate clients. With the default configuration, no webhook.gogs.secret set, Argo CD’s /api/webhook endpoint will cr…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59537">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59531 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59531</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59531</guid>
    <pubDate>Wed, 01 Oct 2025 21:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59531</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 are vulnerable to malicious API requests which can crash the API server and cause denial of service to legitimate clients. Without a configured webhook.bitbucketserver.secret, Argo CD's /api/webhook endpoint crashes when r…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-703</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59531">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-55190 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55190</guid>
    <pubDate>Thu, 04 Sep 2025 23:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-55190</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.0.12 and 3.1.0-rc1 through 3.1.1, API tokens with project-level permissions are able to retrieve sensitive repository credentials (usernames, passwords) through the project details API endpoint, even when the token only has standard application manag…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-47933 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47933</guid>
    <pubDate>Thu, 29 May 2025 20:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-47933</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.13.8, 2.14.13, and 3.0.4, an attacker can perform arbitrary actions on behalf of the victim via the API. Due to the improper filtering of URL protocols in the repository page, an attacker can achieve cross-site scripting with permission to edit the repository. This issue has been patched in versions 2.13…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13484 – A flaw was found in openshift-gitops-operator-container. The openshift.io/cluste...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13484</guid>
    <pubDate>Tue, 28 Jan 2025 18:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13484</strong></p>
  <p>A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can have adverse effects on the platform monitoring stack, as the rule is rolled out cluster-wide when the label is applied.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-40634 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40634</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40634</guid>
    <pubDate>Mon, 22 Jul 2024 18:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-40634</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability in Argo CD, where an unauthenticated attacker can send a specially crafted large JSON payload to the /api/webhook endpoint, causing excessive memory allocation that leads to service disruption by triggering an Out Of Memory (OOM) kill. The issue poses a high risk to the availabil…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40634">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-31989 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It has...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31989</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31989</guid>
    <pubDate>Tue, 21 May 2024 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-31989</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It has been discovered that an unprivileged pod in a different namespace on the same cluster could connect to the Redis server on port 6379. Despite having installed the latest version of the VPC CNI plugin on the EKS cluster, it requires manual enablement through configuration to enforce network policies. This raises conce…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31989">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21662 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21662</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21662</guid>
    <pubDate>Mon, 18 Mar 2024 19:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21662</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can effectively bypass the rate limit and brute force protections by exploiting the application's weak cache-based mechanism. This loophole in security can be combined with other vulnerabilities to attack the default admin account. This flaw undermines a patch for CVE…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21662">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21661 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21661</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21661</guid>
    <pubDate>Mon, 18 Mar 2024 19:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21661</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all users. The issue arises from unsafe manipulation of an array in a multi-threaded environment. The vulnerability is roote…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21661">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-21652 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21652</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21652</guid>
    <pubDate>Mon, 18 Mar 2024 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-21652</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can exploit a chain of vulnerabilities, including a Denial of Service (DoS) flaw and in-memory data storage weakness, to effectively bypass the application's brute force login protection. This is a critical security vulnerability that allows attackers to bypass the br…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21652">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-28175 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Due to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-28175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-28175</guid>
    <pubDate>Wed, 13 Mar 2024 21:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-28175</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Due to the improper URL protocols filtering of links specified in the `link.argocd.argoproj.io` annotations in the application summary component, an attacker can achieve cross-site scripting with elevated permissions. All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to a cross-site scripting (XSS) bug a…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22424 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The Ar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22424</guid>
    <pubDate>Fri, 19 Jan 2024 01:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22424</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.15 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which conta…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-40029 – Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40029</guid>
    <pubDate>Thu, 07 Sep 2023 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-40029</strong></p>
  <p>Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively using Argo CD / kubectl apply. As a result, the full secret body is stored in`kubectl.kubernetes.io/last-applied-configuration` annotation. pull request #7139 introduced the ability to manage cluster labels and annotations. Since clusters are stored as secrets it also exposes the…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-23947 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All Ar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23947</guid>
    <pubDate>Thu, 16 Feb 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-23947</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All Argo CD versions starting with 2.3.0-rc1 and prior to 2.3.17, 2.4.23  2.5.11, and 2.6.2 are vulnerable to an improper authorization bug which allows users who have the ability to update at least one cluster secret to update any cluster secret. The attacker could use this access to escalate privileges (potentially contro…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23947">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22736 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22736</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22736</guid>
    <pubDate>Thu, 26 Jan 2023 21:18:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22736</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions starting with 2.5.0-rc1 and above, prior to 2.5.8, and version 2.6.0-rc4, are vulnerable to an authorization bypass bug which allows a malicious Argo CD user to deploy Applications outside the configured allowed namespaces. Reconciled Application namespaces are specified as a comma-delimited list of glob patterns.…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22736">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-22482 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22482</guid>
    <pubDate>Thu, 26 Jan 2023 21:18:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-22482</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions of Argo CD starting with v1.8.2 and prior to 2.3.13, 2.4.19, 2.5.6, and 2.6.0-rc-3  are vulnerable to an improper authorization bug causing the API to accept certain invalid tokens. OIDC providers include an `aud` (audience) claim in signed tokens. The value of that claim specifies the intended audience(s) of the t…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31105 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31105</guid>
    <pubDate>Tue, 12 Jul 2022 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31105</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.4.0 and prior to 2.2.11, 2.3.6, and 2.4.5 is vulnerable to an improper certificate validation bug which could cause Argo CD to trust a malicious (or otherwise untrustworthy) OpenID Connect (OIDC) provider. A patch for this vulnerability has been released in Argo CD versions 2.4.5, 2.3.6, and…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-1025 – All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-1025</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-1025</guid>
    <pubDate>Tue, 12 Jul 2022 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-1025</strong></p>
  <p>All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admin-level.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-1025">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-31035 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31035</guid>
    <pubDate>Mon, 27 Jun 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-31035</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.0.0 are vulnerable to a cross-site scripting (XSS) bug allowing a malicious user to inject a `javascript:` link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). The script would be capable of doing anything w…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31034 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31034</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31034</guid>
    <pubDate>Mon, 27 Jun 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31034</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v0.11.0 are vulnerable to a variety of attacks when an SSO login is initiated from the Argo CD CLI or UI. The vulnerabilities are due to the use of insufficiently random values in parameters in Oauth2/OIDC login flows. In each case, using a relatively-predictable (time-based) seed in a…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31034">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-29165 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A crit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29165</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29165</guid>
    <pubDate>Fri, 20 May 2022 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-29165</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A critical vulnerability has been discovered in Argo CD starting with version 1.4.0 and prior to versions 2.1.15, 2.2.9, and 2.3.4 which would allow unauthenticated users to impersonate as any Argo CD user or role, including the `admin` user, by sending a specifically crafted JSON Web Token (JWT) along with the request. In…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29165">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-24768 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24768</guid>
    <pubDate>Wed, 23 Mar 2022 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-24768</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All unpatched versions of Argo CD starting with 1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admin-level. Versions starting with 0.8.0 and 0.5.0 contain limited versions of this issue. To perform exploits, an authorized Argo CD user must have p…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24730 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24730</guid>
    <pubDate>Wed, 23 Mar 2022 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24730</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before versions 2.1.11, 2.2.6, and 2.3.0 is vulnerable to a path traversal bug, compounded by an improper access control bug, allowing a malicious user with read-only repository access to leak sensitive files from Argo CD's repo-server. A malicious Argo CD user who has been granted `g…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24348 – Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24348</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24348</guid>
    <pubDate>Fri, 04 Feb 2022 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24348</strong></p>
  <p>Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related to Helm charts because of an error in helmTemplate in repository.go. For example, an attacker may be able to discover credentials stored in a YAML file.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24348">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-26923 – An issue was discovered in Argo CD before 1.8.4. Accessing the endpoint /api/ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26923</guid>
    <pubDate>Mon, 15 Mar 2021 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-26923</strong></p>
  <p>An issue was discovered in Argo CD before 1.8.4. Accessing the endpoint /api/version leaks internal information for the system, and this endpoint is not protected with authentication.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8828 – As of v1.5.0, the default admin password is set to the argocd-server pod name. F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8828</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8828</guid>
    <pubDate>Wed, 08 Apr 2020 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8828</strong></p>
  <p>As of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8828">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
