Argoproj

Argo Cd

54 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.06%
  • Veröffentlicht 19.01.2024 01:15:09
  • Zuletzt bearbeitet 21.11.2024 08:56:15

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.15 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write H...

  • EPSS 0.21%
  • Veröffentlicht 27.09.2023 21:15:09
  • Zuletzt bearbeitet 21.11.2024 08:18:33

Argo CD is a declarative continuous deployment framework for Kubernetes. In Argo CD versions prior to 2.3 (starting at least in v0.1.0, but likely in any version using Helm before 2.3), using a specifically-crafted Helm file could reference external ...

  • EPSS 0.53%
  • Veröffentlicht 07.09.2023 23:15:10
  • Zuletzt bearbeitet 21.11.2024 08:19:45

Argo CD is a declarative continuous deployment for Kubernetes. All versions of ArgoCD starting from v2.4 have a bug where the ArgoCD repo-server component is vulnerable to a Denial-of-Service attack vector. Specifically, the said component extracts a...

Exploit
  • EPSS 0.93%
  • Veröffentlicht 07.09.2023 23:15:09
  • Zuletzt bearbeitet 21.11.2024 08:18:33

Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively using Argo CD / kubectl apply. As a result, the full secret body is stored in`kubectl.kubernetes.io/last-applied-configuration` anno...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 23.08.2023 20:15:08
  • Zuletzt bearbeitet 21.11.2024 08:18:32

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting from version 2.6.0 have a bug where open web terminal sessions do not expire. This bug allows users to send any websocket messages even if the ...

  • EPSS 0.18%
  • Veröffentlicht 16.02.2023 18:15:11
  • Zuletzt bearbeitet 21.11.2024 07:47:09

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All Argo CD versions starting with 2.3.0-rc1 and prior to 2.3.17, 2.4.23 2.5.11, and 2.6.2 are vulnerable to an improper authorization bug which allows users who have the abil...

  • EPSS 0.62%
  • Veröffentlicht 08.02.2023 21:15:10
  • Zuletzt bearbeitet 21.11.2024 07:49:13

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v2.6.0-rc1 have an output sanitization bug which leaks repository access credentials in error messages. These error messages are visible t...

  • EPSS 0.02%
  • Veröffentlicht 26.01.2023 21:18:13
  • Zuletzt bearbeitet 21.11.2024 07:45:19

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions starting with 2.5.0-rc1 and above, prior to 2.5.8, and version 2.6.0-rc4, are vulnerable to an authorization bypass bug which allows a malicious Argo CD user to deploy...

  • EPSS 0.25%
  • Veröffentlicht 26.01.2023 21:18:12
  • Zuletzt bearbeitet 21.11.2024 07:44:53

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions of Argo CD starting with v1.8.2 and prior to 2.3.13, 2.4.19, 2.5.6, and 2.6.0-rc-3 are vulnerable to an improper authorization bug causing the API to accept certain i...

  • EPSS 0.24%
  • Veröffentlicht 12.07.2022 22:15:08
  • Zuletzt bearbeitet 21.11.2024 07:03:54

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.4.0 and prior to 2.2.11, 2.3.6, and 2.4.5 is vulnerable to an improper certificate validation bug which could cause Argo CD to trust a malicious...