<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Argo CD</title>
  <link>https://cvedaily.com/pages/tags/argo-cd.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/argo-cd.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Argo CD</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:51 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-42880 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42880</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42880</guid>
    <pubDate>Thu, 07 May 2026 23:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42880</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism. T…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42880">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43824 – In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows rea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43824</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43824</guid>
    <pubDate>Sat, 02 May 2026 02:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43824</strong></p>
  <p>In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-212</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43824">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6388 – A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6388</guid>
    <pubDate>Wed, 15 Apr 2026 22:17:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6388</strong></p>
  <p>A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a multi-tenant environment, to bypass namespace boundaries. By exploiting insufficient validation, the attacker can trigger unauthorized image updates on applications managed by other tenants. This leads to cross-namespace privilege escalation, impactin…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-1220</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24748 – Kargo manages and automates the promotion of software artifacts. Prior to versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24748</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24748</guid>
    <pubDate>Tue, 27 Jan 2026 22:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24748</strong></p>
  <p>Kargo manages and automates the promotion of software artifacts. Prior to versions 1.8.7, 1.7.7, and 1.6.3, a bug was found with authentication checks on the `GetConfig()` API endpoint. This allowed unauthenticated users to access this endpoint by specifying an `Authorization` header with any non-empty `Bearer` token value, regardless of validity.  This vulnerability did allow for exfiltration of…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24748">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-13888 – A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13888</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13888</guid>
    <pubDate>Mon, 15 Dec 2025 16:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-13888</strong></p>
  <p>A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated permissions in other namespaces, including privileged namespaces. An authenticated attacker can then use these elevated permissions to create privileged workloads that run on master nodes, effectively giving them root access to the entire cluster.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13888">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59538 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. For ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59538</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59538</guid>
    <pubDate>Wed, 01 Oct 2025 21:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59538</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. For versions 2.9.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.6 and 3.0.17, when the webhook.azuredevops.username and webhook.azuredevops.password are not set in the default configuration, the /api/webhook endpoint crashes the entire argocd-server process when it receives an Azure DevOps Push event whose JSON arr…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59538">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59537 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59537</guid>
    <pubDate>Wed, 01 Oct 2025 21:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59537</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 are vulnerable to malicious API requests which can crash the API server and cause denial of service to legitimate clients. With the default configuration, no webhook.gogs.secret set, Argo CD’s /api/webhook endpoint will cr…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59537">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59531 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59531</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59531</guid>
    <pubDate>Wed, 01 Oct 2025 21:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59531</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 are vulnerable to malicious API requests which can crash the API server and cause denial of service to legitimate clients. Without a configured webhook.bitbucketserver.secret, Argo CD's /api/webhook endpoint crashes when r…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-703</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59531">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-55191 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55191</guid>
    <pubDate>Tue, 30 Sep 2025 23:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-55191</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions between 2.1.0 and 2.14.19, 3.2.0-rc1, 3.1.0-rc1 through 3.1.7, and 3.0.0-rc1 through 3.0.18 contain a race condition in the repository credentials handler that can cause the Argo CD server to panic and crash when concurrent operations are performed on the same repository URL. The vulnerability is located in numerou…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-55190 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55190</guid>
    <pubDate>Thu, 04 Sep 2025 23:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-55190</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.0.12 and 3.1.0-rc1 through 3.1.1, API tokens with project-level permissions are able to retrieve sensitive repository credentials (usernames, passwords) through the project details API endpoint, even when the token only has standard application manag…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-47933 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47933</guid>
    <pubDate>Thu, 29 May 2025 20:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-47933</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.13.8, 2.14.13, and 3.0.4, an attacker can perform arbitrary actions on behalf of the victim via the API. Due to the improper filtering of URL protocols in the repository page, an attacker can achieve cross-site scripting with permission to edit the repository. This issue has been patched in versions 2.13…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-23216 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23216</guid>
    <pubDate>Thu, 30 Jan 2025 16:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-23216</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository. The vulnerability assumes the user has write access to the repository and can exploit it, either intentionally or unintentionally, by committing an…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13484 – A flaw was found in openshift-gitops-operator-container. The openshift.io/cluste...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13484</guid>
    <pubDate>Tue, 28 Jan 2025 18:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13484</strong></p>
  <p>A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can have adverse effects on the platform monitoring stack, as the rule is rolled out cluster-wide when the label is applied.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-41666 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41666</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41666</guid>
    <pubDate>Wed, 24 Jul 2024 18:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-41666</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD has a Web-based terminal that allows users to get a shell inside a running pod, just as they would with kubectl exec. Starting in version 2.6.0, when the administrator enables this function and grants permission to the user `p, role:myrole, exec, create, */*, allow`, even if the user revokes this permission, the use…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41666">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-40634 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40634</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40634</guid>
    <pubDate>Mon, 22 Jul 2024 18:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-40634</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability in Argo CD, where an unauthenticated attacker can send a specially crafted large JSON payload to the /api/webhook endpoint, causing excessive memory allocation that leads to service disruption by triggering an Out Of Memory (OOM) kill. The issue poses a high risk to the availabil…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40634">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-37152 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37152</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37152</guid>
    <pubDate>Thu, 06 Jun 2024 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-37152</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by  /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37152">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-36106 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It’s p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36106</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36106</guid>
    <pubDate>Thu, 06 Jun 2024 15:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-36106</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It’s possible for authenticated users to enumerate clusters by name by inspecting error messages. It’s also possible to enumerate the names of projects with project-scoped clusters if you know the names of the clusters. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36106">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-31989 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It has...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31989</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31989</guid>
    <pubDate>Tue, 21 May 2024 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-31989</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It has been discovered that an unprivileged pod in a different namespace on the same cluster could connect to the Redis server on port 6379. Despite having installed the latest version of the VPC CNI plugin on the EKS cluster, it requires manual enablement through configuration to enforce network policies. This raises conce…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31989">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-32476 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. There ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32476</guid>
    <pubDate>Tue, 14 May 2024 15:36:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-32476</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. There is a Denial of Service (DoS) vulnerability via OOM using jq in ignoreDifferences. This vulnerability has been patched in version(s) 2.10.7, 2.9.12 and 2.8.16.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-31990 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The AP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31990</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31990</guid>
    <pubDate>Mon, 15 Apr 2024 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-31990</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The API server does not enforce project sourceNamespaces which allows attackers to use the UI to edit resources which should only be mutable via gitops. This vulenrability is fixed in 2.10.7, 2.9.12, and 2.8.16.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31990">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-29893 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-29893</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-29893</guid>
    <pubDate>Fri, 29 Mar 2024 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-29893</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of ArgoCD starting from v2.4 have a bug where the ArgoCD repo-server component is vulnerable to a Denial-of-Service attack vector. Specifically,  it's possible to crash the repo server component through an out of memory error by pointing it to a malicious Helm registry. The loadRepoIndex() function in the ArgoC…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29893">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21662 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21662</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21662</guid>
    <pubDate>Mon, 18 Mar 2024 19:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21662</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can effectively bypass the rate limit and brute force protections by exploiting the application's weak cache-based mechanism. This loophole in security can be combined with other vulnerabilities to attack the default admin account. This flaw undermines a patch for CVE…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21662">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21661 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21661</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21661</guid>
    <pubDate>Mon, 18 Mar 2024 19:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21661</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application inoperable and affecting all users. The issue arises from unsafe manipulation of an array in a multi-threaded environment. The vulnerability is roote…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21661">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-21652 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21652</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21652</guid>
    <pubDate>Mon, 18 Mar 2024 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-21652</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can exploit a chain of vulnerabilities, including a Denial of Service (DoS) flaw and in-memory data storage weakness, to effectively bypass the application's brute force login protection. This is a critical security vulnerability that allows attackers to bypass the br…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21652">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-28175 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Due to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-28175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-28175</guid>
    <pubDate>Wed, 13 Mar 2024 21:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-28175</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Due to the improper URL protocols filtering of links specified in the `link.argocd.argoproj.io` annotations in the application summary component, an attacker can achieve cross-site scripting with elevated permissions. All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to a cross-site scripting (XSS) bug a…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-50726 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50726</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50726</guid>
    <pubDate>Wed, 13 Mar 2024 21:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-50726</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows developers to temporarily override an Application's manifests with locally-defined manifests. Use of the feature should generally be limited to highly-trusted users, since it allows the user to bypass any merge protections in git. An improper validation bug allows users who hav…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50726">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22424 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The Ar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22424</guid>
    <pubDate>Fri, 19 Jan 2024 01:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22424</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.15 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which conta…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40026 – Argo CD is a declarative continuous deployment framework for Kubernetes. In Argo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40026</guid>
    <pubDate>Wed, 27 Sep 2023 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40026</strong></p>
  <p>Argo CD is a declarative continuous deployment framework for Kubernetes. In Argo CD versions prior to 2.3 (starting at least in v0.1.0, but likely in any version using Helm before 2.3), using a specifically-crafted Helm file could reference external Helm charts handled by the same repo-server to leak values, or files from the referenced Helm Chart. This was possible because Helm paths were predic…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40584 – Argo CD is a declarative continuous deployment for Kubernetes. All versions of A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40584</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40584</guid>
    <pubDate>Thu, 07 Sep 2023 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40584</strong></p>
  <p>Argo CD is a declarative continuous deployment for Kubernetes. All versions of ArgoCD starting from v2.4 have a bug where the ArgoCD repo-server component is vulnerable to a Denial-of-Service attack vector. Specifically, the said component extracts a user-controlled tar.gz file without validating the size of its inner files. As a result, a malicious, low-privileged user can send a malicious tar.g…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40584">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-40029 – Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40029</guid>
    <pubDate>Thu, 07 Sep 2023 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-40029</strong></p>
  <p>Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively using Argo CD / kubectl apply. As a result, the full secret body is stored in`kubectl.kubernetes.io/last-applied-configuration` annotation. pull request #7139 introduced the ability to manage cluster labels and annotations. Since clusters are stored as secrets it also exposes the…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40025 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40025</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40025</guid>
    <pubDate>Wed, 23 Aug 2023 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40025</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting from version 2.6.0 have a bug where open web terminal sessions do not expire. This bug allows users to send any websocket messages even if the token has already expired. The most straightforward scenario is when a user opens the terminal view and leaves it open for an extended period. This a…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40025">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-41354 – An access control issue in Argo CD v2.4.12 and below allows unauthenticated atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41354</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41354</guid>
    <pubDate>Mon, 27 Mar 2023 14:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-41354</strong></p>
  <p>An access control issue in Argo CD v2.4.12 and below allows unauthenticated attackers to enumerate existing applications.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41354">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-23947 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All Ar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23947</guid>
    <pubDate>Thu, 16 Feb 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-23947</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All Argo CD versions starting with 2.3.0-rc1 and prior to 2.3.17, 2.4.23  2.5.11, and 2.6.2 are vulnerable to an improper authorization bug which allows users who have the ability to update at least one cluster secret to update any cluster secret. The attacker could use this access to escalate privileges (potentially contro…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23947">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-25163 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25163</guid>
    <pubDate>Wed, 08 Feb 2023 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-25163</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v2.6.0-rc1 have an output sanitization bug which leaks repository access credentials in error messages. These error messages are visible to the user, and they are logged. The error message is visible when a user attempts to create or update an Application via the Argo CD API (and theref…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22736 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22736</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22736</guid>
    <pubDate>Thu, 26 Jan 2023 21:18:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22736</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions starting with 2.5.0-rc1 and above, prior to 2.5.8, and version 2.6.0-rc4, are vulnerable to an authorization bypass bug which allows a malicious Argo CD user to deploy Applications outside the configured allowed namespaces. Reconciled Application namespaces are specified as a comma-delimited list of glob patterns.…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22736">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-22482 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22482</guid>
    <pubDate>Thu, 26 Jan 2023 21:18:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-22482</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions of Argo CD starting with v1.8.2 and prior to 2.3.13, 2.4.19, 2.5.6, and 2.6.0-rc-3  are vulnerable to an improper authorization bug causing the API to accept certain invalid tokens. OIDC providers include an `aud` (audience) claim in signed tokens. The value of that claim specifies the intended audience(s) of the t…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31105 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31105</guid>
    <pubDate>Tue, 12 Jul 2022 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31105</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.4.0 and prior to 2.2.11, 2.3.6, and 2.4.5 is vulnerable to an improper certificate validation bug which could cause Argo CD to trust a malicious (or otherwise untrustworthy) OpenID Connect (OIDC) provider. A patch for this vulnerability has been released in Argo CD versions 2.4.5, 2.3.6, and…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2022-31102 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31102</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31102</guid>
    <pubDate>Tue, 12 Jul 2022 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2022-31102</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with 2.3.0 and prior to 2.3.6 and 2.4.5 is vulnerable to a cross-site scripting (XSS) bug which could allow an attacker to inject arbitrary JavaScript in the `/auth/callback` page in a victim's browser. This vulnerability only affects Argo CD instances which have single sign on (SSO) enabled. The exploit al…</p>
  <p><strong>CVSS:</strong> 2.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31102">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-1025 – All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-1025</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-1025</guid>
    <pubDate>Tue, 12 Jul 2022 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-1025</strong></p>
  <p>All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admin-level.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-1025">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31036 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31036</guid>
    <pubDate>Mon, 27 Jun 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31036</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.3.0 are vulnerable to a symlink following bug allowing a malicious user with repository write access to leak sensitive YAML files from Argo CD's repo-server. A malicious Argo CD user with write access for a repository which is (or may be) used in a Helm-type Application may commit a…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-31035 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31035</guid>
    <pubDate>Mon, 27 Jun 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-31035</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.0.0 are vulnerable to a cross-site scripting (XSS) bug allowing a malicious user to inject a `javascript:` link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). The script would be capable of doing anything w…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31034 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31034</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31034</guid>
    <pubDate>Mon, 27 Jun 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31034</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v0.11.0 are vulnerable to a variety of attacks when an SSO login is initiated from the Argo CD CLI or UI. The vulnerabilities are due to the use of insufficiently random values in parameters in Oauth2/OIDC login flows. In each case, using a relatively-predictable (time-based) seed in a…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31034">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31016 – Argo CD is a declarative continuous deployment for Kubernetes. Argo CD versions ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31016</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31016</guid>
    <pubDate>Sat, 25 Jun 2022 08:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31016</strong></p>
  <p>Argo CD is a declarative continuous deployment for Kubernetes. Argo CD versions v0.7.0 and later are vulnerable to an uncontrolled memory consumption bug, allowing an authorized malicious user to crash the repo-server service, resulting in a Denial of Service. The attacker must be an authenticated Argo CD user authorized to deploy Applications from a repository which contains (or can be made to c…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31016">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-29165 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A crit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29165</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29165</guid>
    <pubDate>Fri, 20 May 2022 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-29165</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A critical vulnerability has been discovered in Argo CD starting with version 1.4.0 and prior to versions 2.1.15, 2.2.9, and 2.3.4 which would allow unauthenticated users to impersonate as any Argo CD user or role, including the `admin` user, by sending a specifically crafted JSON Web Token (JWT) along with the request. In…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29165">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-24905 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24905</guid>
    <pubDate>Fri, 20 May 2022 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-24905</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was found in Argo CD prior to versions 2.3.4, 2.2.9, and 2.1.15 that allows an attacker to spoof error messages on the login screen when single sign on (SSO) is enabled. In order to exploit this vulnerability, an attacker would have to trick the victim to visit a specially crafted URL which contains the mess…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-24904 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24904</guid>
    <pubDate>Fri, 20 May 2022 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-24904</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.7.0 and prior to versions 2.1.15m 2.2.9, and 2.3.4 is vulnerable to a symlink following bug allowing a malicious user with repository write access to leak sensitive files from Argo CD's repo-server. A malicious Argo CD user with write access for a repository which is (or may be) used in a dir…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-24768 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24768</guid>
    <pubDate>Wed, 23 Mar 2022 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-24768</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All unpatched versions of Argo CD starting with 1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admin-level. Versions starting with 0.8.0 and 0.5.0 contain limited versions of this issue. To perform exploits, an authorized Argo CD user must have p…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-24731 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24731</guid>
    <pubDate>Wed, 23 Mar 2022 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-24731</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.5.0 but before versions 2.1.11, 2.2.6, and 2.3.0 is vulnerable to a path traversal vulnerability, allowing a malicious user with read/write access to leak sensitive files from Argo CD's repo-server. A malicious Argo CD user who has been granted `create` or `update` access to Applications can…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24730 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24730</guid>
    <pubDate>Wed, 23 Mar 2022 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24730</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before versions 2.1.11, 2.2.6, and 2.3.0 is vulnerable to a path traversal bug, compounded by an improper access control bug, allowing a malicious user with read-only repository access to leak sensitive files from Argo CD's repo-server. A malicious Argo CD user who has been granted `g…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-3557 – A flaw was found in argocd. Any unprivileged user is able to deploy argocd in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3557</guid>
    <pubDate>Wed, 16 Feb 2022 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-3557</strong></p>
  <p>A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-server, the unprivileged user is able to read all resources of the cluster including all secrets which might enable privilege escalations. The highest threat from this vulnerability is to data confidentiality.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3557">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24348 – Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24348</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24348</guid>
    <pubDate>Fri, 04 Feb 2022 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24348</strong></p>
  <p>Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related to Helm charts because of an error in helmTemplate in repository.go. For example, an attacker may be able to discover credentials stored in a YAML file.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24348">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-23135 – Exposure of System Data to an Unauthorized Control Sphere vulnerability in web U...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-23135</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-23135</guid>
    <pubDate>Wed, 12 May 2021 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-23135</strong></p>
  <p>Exposure of System Data to an Unauthorized Control Sphere vulnerability in web UI of Argo CD allows attacker to cause leaked secret data into web UI error messages and logs. This issue affects Argo CD 1.8 versions prior to 1.8.7; 1.7 versions prior to 1.7.14.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-23135">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-26924 – An issue was discovered in Argo CD before 1.8.4. Browser XSS protection is not a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26924</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26924</guid>
    <pubDate>Mon, 15 Mar 2021 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-26924</strong></p>
  <p>An issue was discovered in Argo CD before 1.8.4. Browser XSS protection is not activated due to the missing XSS protection header.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26924">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-26923 – An issue was discovered in Argo CD before 1.8.4. Accessing the endpoint /api/ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26923</guid>
    <pubDate>Mon, 15 Mar 2021 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-26923</strong></p>
  <p>An issue was discovered in Argo CD before 1.8.4. Accessing the endpoint /api/version leaks internal information for the system, and this endpoint is not protected with authentication.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-23347 – The package github.com/argoproj/argo-cd/cmd before 1.7.13, from 1.8.0 and before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-23347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-23347</guid>
    <pubDate>Wed, 03 Mar 2021 10:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-23347</strong></p>
  <p>The package github.com/argoproj/argo-cd/cmd before 1.7.13, from 1.8.0 and before 1.8.6 are vulnerable to Cross-site Scripting (XSS) the SSO provider connected to Argo CD would have to send back a malicious error message containing JavaScript to the user.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-23347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-26921 – In util/session/sessionmanager.go in Argo CD before 1.8.4, tokens continue to wo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26921</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26921</guid>
    <pubDate>Tue, 09 Feb 2021 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-26921</strong></p>
  <p>In util/session/sessionmanager.go in Argo CD before 1.8.4, tokens continue to work even when the user account is disabled.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26921">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8828 – As of v1.5.0, the default admin password is set to the argocd-server pod name. F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8828</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8828</guid>
    <pubDate>Wed, 08 Apr 2020 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8828</strong></p>
  <p>As of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8828">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
