First published: Mon Mar 15 2021(Updated: )
An issue was discovered in Argo CD before 1.8.4. Accessing the endpoint /api/version leaks internal information for the system, and this endpoint is not protected with authentication.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linuxfoundation Argo-cd | <1.7.12 | |
Linuxfoundation Argo-cd | >=1.8.0<1.8.4 | |
Argoproj Argo Cd | <1.7.12 | |
Argoproj Argo Cd | >=1.8.0<1.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26923 is a vulnerability discovered in Argo CD before version 1.8.4 that allows unauthorized access to internal system information via the /api/version endpoint.
CVE-2021-26923 has a severity rating of 7.5, which is classified as high.
CVE-2021-26923 affects Argo CD versions 1.7.12 and versions between 1.8.0 and 1.8.4 (inclusive).
No, the /api/version endpoint in Argo CD is not protected with authentication.
To fix CVE-2021-26923, upgrade Argo CD to version 1.8.4 or higher.