The package github.com/argoproj/argo-cd/cmd before 1.7.13, from 1.8.0 and before 1.8.6 are vulnerable to Cross-site Scripting (XSS) the SSO provider connected to Argo CD would have to send back a malicious error message containing JavaScript to the user.
2021-03-03T10:15:13.753
2024-11-21T05:51:33.100
Modified
CVSSv3.1: 4.7 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | argoproj | argo_cd | < 1.7.13 | Yes |
Application | argoproj | argo_cd | < 1.8.6 | Yes |