Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.
2024-06-06T16:15:13.190
2024-11-21T09:23:18.570
Modified
CVSSv3.1: 5.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | argoproj | argo_cd | < 2.9.17 | Yes |
Application | argoproj | argo_cd | < 2.10.12 | Yes |
Application | argoproj | argo_cd | < 2.11.3 | Yes |