Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository. The vulnerability assumes the user has write access to the repository and can exploit it, either intentionally or unintentionally, by committing an invalid Secret to repository and triggering a Sync. Once exploited, any user with read access to Argo CD can view the exposed secret data. The vulnerability is fixed in v2.13.4, v2.12.10, and v2.11.13.
History

Fri, 31 Jan 2025 01:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 30 Jan 2025 15:45:00 +0000

Type Values Removed Values Added
Description Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository. The vulnerability assumes the user has write access to the repository and can exploit it, either intentionally or unintentionally, by committing an invalid Secret to repository and triggering a Sync. Once exploited, any user with read access to Argo CD can view the exposed secret data. The vulnerability is fixed in v2.13.4, v2.12.10, and v2.11.13.
Title Argo CD does not scrub secret values from patch errors
Weaknesses CWE-200
CWE-209
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-02-12T19:51:12.285Z

Reserved: 2025-01-13T17:15:41.051Z

Link: CVE-2025-23216

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-01-30T16:15:31.473

Modified: 2025-01-30T16:15:31.473

Link: CVE-2025-23216

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-01-30T15:30:05Z

Links: CVE-2025-23216 - Bugzilla