Argo CD is a declarative continuous deployment for Kubernetes. Argo CD versions v0.7.0 and later are vulnerable to an uncontrolled memory consumption bug, allowing an authorized malicious user to crash the repo-server service, resulting in a Denial of Service. The attacker must be an authenticated Argo CD user authorized to deploy Applications from a repository which contains (or can be made to contain) a large file. The fix for this vulnerability is available in versions 2.3.5, 2.2.10, 2.1.16, and later. There are no known workarounds. Users are recommended to upgrade.
2022-06-25T08:15:09.307
2024-11-21T07:03:43.183
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:N/A:P
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | argoproj | argo_cd | < 2.1.16 | Yes |
Application | argoproj | argo_cd | < 2.2.10 | Yes |
Application | argoproj | argo_cd | < 2.3.5 | Yes |
Application | argoproj | argo_cd | < 2.4.1 | Yes |