CVE-2024-28175
- EPSS 0.48%
- Veröffentlicht 13.03.2024 21:16:00
- Zuletzt bearbeitet 09.01.2025 17:05:59
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Due to the improper URL protocols filtering of links specified in the `link.argocd.argoproj.io` annotations in the application summary component, an attacker can achieve cross-...
CVE-2023-50726
- EPSS 0.02%
- Veröffentlicht 13.03.2024 21:15:54
- Zuletzt bearbeitet 02.06.2025 14:35:20
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows developers to temporarily override an Application's manifests with locally-defined manifests. Use of the feature should generally...
CVE-2024-22424
- EPSS 0.06%
- Veröffentlicht 19.01.2024 01:15:09
- Zuletzt bearbeitet 21.11.2024 08:56:15
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.15 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write H...
CVE-2023-40026
- EPSS 0.21%
- Veröffentlicht 27.09.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 08:18:33
Argo CD is a declarative continuous deployment framework for Kubernetes. In Argo CD versions prior to 2.3 (starting at least in v0.1.0, but likely in any version using Helm before 2.3), using a specifically-crafted Helm file could reference external ...
CVE-2023-40584
- EPSS 0.54%
- Veröffentlicht 07.09.2023 23:15:10
- Zuletzt bearbeitet 21.11.2024 08:19:45
Argo CD is a declarative continuous deployment for Kubernetes. All versions of ArgoCD starting from v2.4 have a bug where the ArgoCD repo-server component is vulnerable to a Denial-of-Service attack vector. Specifically, the said component extracts a...
CVE-2023-40029
- EPSS 0.92%
- Veröffentlicht 07.09.2023 23:15:09
- Zuletzt bearbeitet 21.11.2024 08:18:33
Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively using Argo CD / kubectl apply. As a result, the full secret body is stored in`kubectl.kubernetes.io/last-applied-configuration` anno...
CVE-2023-40025
- EPSS 0.18%
- Veröffentlicht 23.08.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 08:18:32
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting from version 2.6.0 have a bug where open web terminal sessions do not expire. This bug allows users to send any websocket messages even if the ...
CVE-2023-23947
- EPSS 0.35%
- Veröffentlicht 16.02.2023 18:15:11
- Zuletzt bearbeitet 21.11.2024 07:47:09
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All Argo CD versions starting with 2.3.0-rc1 and prior to 2.3.17, 2.4.23 2.5.11, and 2.6.2 are vulnerable to an improper authorization bug which allows users who have the abil...
CVE-2023-25163
- EPSS 0.12%
- Veröffentlicht 08.02.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:49:13
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v2.6.0-rc1 have an output sanitization bug which leaks repository access credentials in error messages. These error messages are visible t...
CVE-2023-22736
- EPSS 0.13%
- Veröffentlicht 26.01.2023 21:18:13
- Zuletzt bearbeitet 21.11.2024 07:45:19
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions starting with 2.5.0-rc1 and above, prior to 2.5.8, and version 2.6.0-rc4, are vulnerable to an authorization bypass bug which allows a malicious Argo CD user to deploy...