Argoproj

Argo Cd

54 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.64%
  • Veröffentlicht 06.06.2024 15:15:45
  • Zuletzt bearbeitet 21.11.2024 09:21:37

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It’s possible for authenticated users to enumerate clusters by name by inspecting error messages. It’s also possible to enumerate the names of projects with project-scoped clus...

Exploit
  • EPSS 9.09%
  • Veröffentlicht 21.05.2024 19:15:09
  • Zuletzt bearbeitet 09.01.2025 16:56:47

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It has been discovered that an unprivileged pod in a different namespace on the same cluster could connect to the Redis server on port 6379. Despite having installed the latest...

  • EPSS 0.42%
  • Veröffentlicht 14.05.2024 15:36:25
  • Zuletzt bearbeitet 09.01.2025 16:59:02

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. There is a Denial of Service (DoS) vulnerability via OOM using jq in ignoreDifferences. This vulnerability has been patched in version(s) 2.10.7, 2.9.12 and 2.8.16.

  • EPSS 0.11%
  • Veröffentlicht 15.04.2024 20:15:11
  • Zuletzt bearbeitet 09.01.2025 17:04:35

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The API server does not enforce project sourceNamespaces which allows attackers to use the UI to edit resources which should only be mutable via gitops. This vulenrability is f...

  • EPSS 0.61%
  • Veröffentlicht 29.03.2024 15:15:12
  • Zuletzt bearbeitet 09.01.2025 14:42:05

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of ArgoCD starting from v2.4 have a bug where the ArgoCD repo-server component is vulnerable to a Denial-of-Service attack vector. Specifically, it's possible to ...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 18.03.2024 19:15:06
  • Zuletzt bearbeitet 09.01.2025 17:13:17

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can effectively bypass the rate limit and brute force protections by exploiting the application's weak cache-based mech...

Exploit
  • EPSS 2.18%
  • Veröffentlicht 18.03.2024 19:15:06
  • Zuletzt bearbeitet 09.01.2025 17:09:38

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can exploit a critical flaw in the application to initiate a Denial of Service (DoS) attack, rendering the application ...

  • EPSS 0.07%
  • Veröffentlicht 18.03.2024 18:15:09
  • Zuletzt bearbeitet 09.01.2025 17:07:47

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can exploit a chain of vulnerabilities, including a Denial of Service (DoS) flaw and in-memory data storage weakness, t...

  • EPSS 0.48%
  • Veröffentlicht 13.03.2024 21:16:00
  • Zuletzt bearbeitet 09.01.2025 17:05:59

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Due to the improper URL protocols filtering of links specified in the `link.argocd.argoproj.io` annotations in the application summary component, an attacker can achieve cross-...

  • EPSS 0.02%
  • Veröffentlicht 13.03.2024 21:15:54
  • Zuletzt bearbeitet 02.06.2025 14:35:20

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows developers to temporarily override an Application's manifests with locally-defined manifests. Use of the feature should generally...