Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-21652


Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can exploit a chain of vulnerabilities, including a Denial of Service (DoS) flaw and in-memory data storage weakness, to effectively bypass the application's brute force login protection. This is a critical security vulnerability that allows attackers to bypass the brute force login protection mechanism. Not only can they crash the service affecting all users, but they can also make unlimited login attempts, increasing the risk of account compromise. Versions 2.8.13, 2.9.9, and 2.10.4 contain a patch for this issue.


Published

2024-03-18T18:15:09.697

Last Modified

2025-01-09T17:07:47.467

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-307
  • Type: Primary
    CWE-307

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application argoproj argo_cd < 2.8.13 Yes
Application argoproj argo_cd < 2.9.9 Yes
Application argoproj argo_cd < 2.10.4 Yes

References