Description
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. There is a Denial of Service (DoS) vulnerability via OOM using jq in ignoreDifferences. This vulnerability has been patched in version(s) 2.10.7, 2.9.12 and 2.8.16.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1173 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. There is a Denial of Service (DoS) vulnerability via OOM using jq in ignoreDifferences. This vulnerability has been patched in version(s) 2.10.7, 2.9.12 and 2.8.16. |
Github GHSA |
GHSA-9m6p-x4h2-6frq | Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences |
References
History
Thu, 09 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Argoproj
Argoproj argo Cd |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Argoproj
Argoproj argo Cd |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T02:13:38.994Z
Reserved: 2024-04-12T19:41:51.167Z
Link: CVE-2024-32476
Updated: 2024-08-02T02:13:38.994Z
Status : Analyzed
Published: 2024-05-14T15:36:25.953
Modified: 2025-01-09T16:59:02.680
Link: CVE-2024-32476
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA