7.7
CVE-2026-43824
- EPSS 0.01%
- Veröffentlicht 02.05.2026 01:20:33
- Zuletzt bearbeitet 05.05.2026 19:47:31
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerargoproj
≫
Produkt
Argo CD
Default Statusunaffected
Version
3.2.0
Version <
3.2.11
Status
affected
Version
3.3.0
Version <
3.3.9
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.01% | 0.02 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cve@mitre.org | 7.7 | 3.1 | 4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
|
CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer
The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.