Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The API server does not enforce project sourceNamespaces which allows attackers to use the UI to edit resources which should only be mutable via gitops. This vulenrability is fixed in 2.10.7, 2.9.12, and 2.8.16.
Metrics
Affected Vendors & Products
References
History
Thu, 09 Jan 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Argoproj
Argoproj argo Cd |
|
CPEs | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* | |
Vendors & Products |
Argoproj
Argoproj argo Cd |

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T01:59:50.786Z
Reserved: 2024-04-08T13:48:37.491Z
Link: CVE-2024-31990

Updated: 2024-04-23T18:46:13.817Z

Status : Analyzed
Published: 2024-04-15T20:15:11.127
Modified: 2025-01-09T17:04:35.590
Link: CVE-2024-31990
