An access control issue in Argo CD v2.4.12 and below allows unauthenticated attackers to enumerate existing applications.
2023-03-27T14:15:07.557
2024-11-21T07:23:06.407
Modified
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | linuxfoundation | argo-cd | < 2.4.28 | Yes |
Application | linuxfoundation | argo-cd | < 2.5.16 | Yes |
Application | linuxfoundation | argo-cd | < 2.6.7 | Yes |