Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-31990


Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The API server does not enforce project sourceNamespaces which allows attackers to use the UI to edit resources which should only be mutable via gitops. This vulenrability is fixed in 2.10.7, 2.9.12, and 2.8.16.


Published

2024-04-15T20:15:11.127

Last Modified

2025-01-09T17:04:35.590

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.8 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-863
  • Type: Primary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application argoproj argo_cd < 2.8.16 Yes
Application argoproj argo_cd < 2.9.12 Yes
Application argoproj argo_cd < 2.10.7 Yes

References