All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admin-level.
2022-07-12T21:15:09.277
2024-11-21T06:39:52.887
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | argoproj | argo_cd | ≤ 2.1.12 | Yes |
Application | argoproj | argo_cd | ≤ 2.2.7 | Yes |
Application | argoproj | argo_cd | ≤ 2.3.1 | Yes |