Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The API server does not enforce project sourceNamespaces which allows attackers to use the UI to edit resources which should only be mutable via gitops. This vulenrability is fixed in 2.10.7, 2.9.12, and 2.8.16.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1062 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The API server does not enforce project sourceNamespaces which allows attackers to use the UI to edit resources which should only be mutable via gitops. This vulenrability is fixed in 2.10.7, 2.9.12, and 2.8.16. |
Github GHSA |
GHSA-2gvw-w6fj-7m3c | Argo CD's API server does not enforce project sourceNamespaces |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 09 Jan 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Argoproj
Argoproj argo Cd |
|
| CPEs | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Argoproj
Argoproj argo Cd |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T01:59:50.786Z
Reserved: 2024-04-08T13:48:37.491Z
Link: CVE-2024-31990
Updated: 2024-04-23T18:46:13.817Z
Status : Analyzed
Published: 2024-04-15T20:15:11.127
Modified: 2025-01-09T17:04:35.590
Link: CVE-2024-31990
OpenCVE Enrichment
No data.
EUVD
Github GHSA