CVE-2024-37152

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
06/06/2024
Last modified:
18/09/2024

Description

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* 2.9.3 (including) 2.9.17 (excluding)
cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* 2.10.0 (including) 2.10.12 (excluding)
cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:* 2.11.0 (including) 2.11.3 (excluding)