Skip to main content

Vendor/product archive

argoproj / argo_cd CVEs

Beta · best-effort

57 CVEs tagged to argoproj / argo_cd12 Critical, 18 High, 26 Medium, 1 Low, 0 Unrated.

CVE-2023-40584

Published Sep 7, 2023

Argo CD is a declarative continuous deployment for Kubernetes. All versions of ArgoCD starting from v2.4 have a bug where the ArgoCD repo-server component is vulnerable to a Denia…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40029

Published Sep 7, 2023

Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively using Argo CD / kubectl apply. As a result, the full secret b…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-40025

Published Aug 23, 2023

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting from version 2.6.0 have a bug where open web terminal sessions do not ex…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23947

Published Feb 16, 2023

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All Argo CD versions starting with 2.3.0-rc1 and prior to 2.3.17, 2.4.23 2.5.11, and 2.6.2 are vulnerabl…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-25163

Published Feb 8, 2023

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v2.6.0-rc1 have an output sanitization bug which leaks repository a…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22736

Published Jan 26, 2023

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions starting with 2.5.0-rc1 and above, prior to 2.5.8, and version 2.6.0-rc4, are vulnerable to an a…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22482

Published Jan 26, 2023

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions of Argo CD starting with v1.8.2 and prior to 2.3.13, 2.4.19, 2.5.6, and 2.6.0-rc-3 are vulnerab…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-31102

Published Jul 12, 2022

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with 2.3.0 and prior to 2.3.6 and 2.4.5 is vulnerable to a cross-site scripting (XSS) bu…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-1025

Published Jul 12, 2022

All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31036

Published Jun 27, 2022

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.3.0 are vulnerable to a symlink following bug allowing a malicio…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31035

Published Jun 27, 2022

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.0.0 are vulnerable to a cross-site scripting (XSS) bug allowing…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-31034

Published Jun 27, 2022

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v0.11.0 are vulnerable to a variety of attacks when an SSO login is…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31016

Published Jun 25, 2022

Argo CD is a declarative continuous deployment for Kubernetes. Argo CD versions v0.7.0 and later are vulnerable to an uncontrolled memory consumption bug, allowing an authorized m…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29165

Published May 20, 2022

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A critical vulnerability has been discovered in Argo CD starting with version 1.4.0 and prior to versions…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-24905

Published May 20, 2022

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was found in Argo CD prior to versions 2.3.4, 2.2.9, and 2.1.15 that allows an attacker t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24904

Published May 20, 2022

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.7.0 and prior to versions 2.1.15m 2.2.9, and 2.3.4 is vulnerable to a sym…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24768

Published Mar 23, 2022

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All unpatched versions of Argo CD starting with 1.0.0 are vulnerable to an improper access control bug, a…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-24731

Published Mar 23, 2022

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.5.0 but before versions 2.1.11, 2.2.6, and 2.3.0 is vulnerable to a path…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24730

Published Mar 23, 2022

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before versions 2.1.11, 2.2.6, and 2.3.0 is vulnerable to a path…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3557

Published Feb 16, 2022

A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-server, the unprivileged user is ab…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24348

Published Feb 4, 2022

Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related to Helm charts because of an error in helmTemplate in repository.go. For example, an attacker may be…

CVSS 7.7 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2021-23135

Published May 12, 2021

Exposure of System Data to an Unauthorized Control Sphere vulnerability in web UI of Argo CD allows attacker to cause leaked secret data into web UI error messages and logs. This…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26924

Published Mar 15, 2021

An issue was discovered in Argo CD before 1.8.4. Browser XSS protection is not activated due to the missing XSS protection header.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26923

Published Mar 15, 2021

An issue was discovered in Argo CD before 1.8.4. Accessing the endpoint /api/version leaks internal information for the system, and this endpoint is not protected with authenticat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 26-50 of 57 CVEsPage 2 of 3