Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It’s possible for authenticated users to enumerate clusters by name by inspecting error messages. It’s also possible to enumerate the names of projects with project-scoped clusters if you know the names of the clusters. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.
History

Wed, 07 Aug 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Argoproj
Argoproj argo Cd
CPEs cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*
Vendors & Products Argoproj
Argoproj argo Cd

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-06-06T15:09:36.474Z

Updated: 2024-09-03T15:39:17.996Z

Reserved: 2024-05-20T21:07:48.186Z

Link: CVE-2024-36106

cve-icon Vulnrichment

Updated: 2024-08-02T03:30:13.074Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-06T15:15:45.023

Modified: 2024-08-07T13:57:07.913

Link: CVE-2024-36106

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-06-06T00:00:00Z

Links: CVE-2024-36106 - Bugzilla