Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It’s possible for authenticated users to enumerate clusters by name by inspecting error messages. It’s also possible to enumerate the names of projects with project-scoped clusters if you know the names of the clusters. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.
Metrics
Affected Vendors & Products
References
History
Wed, 07 Aug 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Argoproj
Argoproj argo Cd |
|
CPEs | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* | |
Vendors & Products |
Argoproj
Argoproj argo Cd |

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-03T15:39:17.996Z
Reserved: 2024-05-20T21:07:48.186Z
Link: CVE-2024-36106

Updated: 2024-08-02T03:30:13.074Z

Status : Modified
Published: 2024-06-06T15:15:45.023
Modified: 2024-11-21T09:21:37.303
Link: CVE-2024-36106
