Argoproj

Argo Cd

58 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.84%
  • Veröffentlicht 08.02.2023 21:15:10
  • Zuletzt bearbeitet 21.11.2024 07:49:13

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v2.6.0-rc1 have an output sanitization bug which leaks repository access credentials in error messages. These error messages are visible t...

  • EPSS 0.78%
  • Veröffentlicht 26.01.2023 21:18:13
  • Zuletzt bearbeitet 21.11.2024 07:45:19

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions starting with 2.5.0-rc1 and above, prior to 2.5.8, and version 2.6.0-rc4, are vulnerable to an authorization bypass bug which allows a malicious Argo CD user to deploy...

  • EPSS 0.88%
  • Veröffentlicht 26.01.2023 21:18:12
  • Zuletzt bearbeitet 21.11.2024 07:44:53

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions of Argo CD starting with v1.8.2 and prior to 2.3.13, 2.4.19, 2.5.6, and 2.6.0-rc-3 are vulnerable to an improper authorization bug causing the API to accept certain i...

  • EPSS 0.77%
  • Veröffentlicht 12.07.2022 22:15:08
  • Zuletzt bearbeitet 21.11.2024 07:03:54

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.4.0 and prior to 2.2.11, 2.3.6, and 2.4.5 is vulnerable to an improper certificate validation bug which could cause Argo CD to trust a malicious...

  • EPSS 0.6%
  • Veröffentlicht 12.07.2022 22:15:08
  • Zuletzt bearbeitet 21.11.2024 07:03:53

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with 2.3.0 and prior to 2.3.6 and 2.4.5 is vulnerable to a cross-site scripting (XSS) bug which could allow an attacker to inject arbitrary JavaScript in the `...

Exploit
  • EPSS 1.25%
  • Veröffentlicht 12.07.2022 21:15:09
  • Zuletzt bearbeitet 21.11.2024 06:39:52

All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admin-level.

  • EPSS 0.83%
  • Veröffentlicht 27.06.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 07:03:45

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.3.0 are vulnerable to a symlink following bug allowing a malicious user with repository write access to leak sensitive YAML files from ...

  • EPSS 0.92%
  • Veröffentlicht 27.06.2022 19:15:08
  • Zuletzt bearbeitet 21.11.2024 07:03:45

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.0.0 are vulnerable to a cross-site scripting (XSS) bug allowing a malicious user to inject a `javascript:` link in the UI. When clicked...

  • EPSS 0.89%
  • Veröffentlicht 27.06.2022 19:15:08
  • Zuletzt bearbeitet 21.11.2024 07:03:45

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v0.11.0 are vulnerable to a variety of attacks when an SSO login is initiated from the Argo CD CLI or UI. The vulnerabilities are due to t...

  • EPSS 0.85%
  • Veröffentlicht 25.06.2022 08:15:09
  • Zuletzt bearbeitet 21.11.2024 07:03:43

Argo CD is a declarative continuous deployment for Kubernetes. Argo CD versions v0.7.0 and later are vulnerable to an uncontrolled memory consumption bug, allowing an authorized malicious user to crash the repo-server service, resulting in a Denial o...