CVE-2024-32476

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
14/05/2024
Last modified:
09/01/2025

Description

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. There is a Denial of Service (DoS) vulnerability via OOM using jq in ignoreDifferences. This vulnerability has been patched in version(s) 2.10.7, 2.9.12 and 2.8.16.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* 2.1.0 (including) 2.8.17 (excluding)
cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* 2.9.0 (including) 2.9.13 (excluding)
cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* 2.10.0 (including) 2.10.8 (excluding)