Argoproj

Argo Cd

54 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Published 01.10.2025 21:16:43
  • Last modified 02.10.2025 19:11:46

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. For versions 2.9.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.6 and 3.0.17, when the webhook.azuredevops.username and webhook.azuredevops.password are not set in the...

  • EPSS 0.05%
  • Published 01.10.2025 21:16:43
  • Last modified 02.10.2025 19:11:46

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 are vulnerable to malicious API requests which can crash the API server a...

  • EPSS 0.04%
  • Published 01.10.2025 21:16:43
  • Last modified 02.10.2025 19:11:46

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 are vulnerable to malicious API requests which can crash the API server a...

  • EPSS 0.03%
  • Published 30.09.2025 23:15:29
  • Last modified 02.10.2025 19:12:17

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions between 2.1.0 and 2.14.19, 3.2.0-rc1, 3.1.0-rc1 through 3.1.7, and 3.0.0-rc1 through 3.0.18 contain a race condition in the repository credentials handler that can cau...

Exploit
  • EPSS 0.05%
  • Published 04.09.2025 22:37:52
  • Last modified 19.09.2025 15:20:53

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.0.12 and 3.1.0-rc1 through 3.1.1, API tokens with project-level permissions are able to retrieve sens...

  • EPSS 0.02%
  • Published 29.05.2025 19:30:39
  • Last modified 27.08.2025 02:28:01

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.13.8, 2.14.13, and 3.0.4, an attacker can perform arbitrary actions on behalf of the victim via the API. Due to the improper filtering of URL protocols in t...

  • EPSS 0.08%
  • Published 30.01.2025 16:15:31
  • Last modified 06.06.2025 15:44:21

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository...

Exploit
  • EPSS 0.08%
  • Published 24.07.2024 18:15:05
  • Last modified 09.01.2025 16:54:08

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD has a Web-based terminal that allows users to get a shell inside a running pod, just as they would with kubectl exec. Starting in version 2.6.0, when the administrator ...

Exploit
  • EPSS 2.34%
  • Published 22.07.2024 18:15:03
  • Last modified 09.01.2025 16:55:20

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability in Argo CD, where an unauthenticated attacker can send a specially crafted large JSON payload to the /api/webhook endpoint, causing...

  • EPSS 57.3%
  • Published 06.06.2024 16:15:13
  • Last modified 21.11.2024 09:23:18

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. All sensitive settings are hidden except pa...