CVE-2021-26923: Infoleak
Published Mar 15, 2021
·Updated
An issue was discovered in Argo CD before 1.8.4. Accessing the endpoint /api/version leaks internal information for the system, and this endpoint is not protected with authentication.
Affected Software
4 affected components
argoproj Argo CD<1.7.12
argoproj Argo CD>=1.8.0<1.8.4
linuxfoundation Argo-cd<1.7.12
linuxfoundation Argo-cd>=1.8.0<1.8.4
Remediation
Patch Available
Event History
Mar 15, 2021
CVE Published
via MITRE·02:40 PM
Data Sourced
via MITRE·02:40 PM
Description
Frequently Asked Questions
1
What is CVE-2021-26923?
CVE-2021-26923 is a vulnerability discovered in Argo CD before version 1.8.4 that allows unauthorized access to internal system information via the /api/version endpoint.
2
How severe is CVE-2021-26923?
CVE-2021-26923 has a severity rating of 7.5, which is classified as high.
3
What software versions are affected by CVE-2021-26923?
CVE-2021-26923 affects Argo CD versions 1.7.12 and versions between 1.8.0 and 1.8.4 (inclusive).
4
Is the /api/version endpoint protected with authentication in Argo CD?
No, the /api/version endpoint in Argo CD is not protected with authentication.
5
How can I fix CVE-2021-26923?
To fix CVE-2021-26923, upgrade Argo CD to version 1.8.4 or higher.