Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It’s possible for authenticated users to enumerate clusters by name by inspecting error messages. It’s also possible to enumerate the names of projects with project-scoped clusters if you know the names of the clusters. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.
Metrics
Affected Vendors & Products
References
History
Wed, 07 Aug 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Argoproj
Argoproj argo Cd |
|
CPEs | cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* | |
Vendors & Products |
Argoproj
Argoproj argo Cd |
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-06-06T15:09:36.474Z
Updated: 2024-09-03T15:39:17.996Z
Reserved: 2024-05-20T21:07:48.186Z
Link: CVE-2024-36106
Vulnrichment
Updated: 2024-08-02T03:30:13.074Z
NVD
Status : Modified
Published: 2024-06-06T15:15:45.023
Modified: 2024-11-21T09:21:37.303
Link: CVE-2024-36106
Redhat