First published: Mon Mar 15 2021(Updated: )
An issue was discovered in Argo CD before 1.8.4. Browser XSS protection is not activated due to the missing XSS protection header.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linuxfoundation Argo-cd | <1.7.12 | |
Linuxfoundation Argo-cd | >=1.8.0<1.8.4 | |
Argoproj Argo Cd | <1.7.12 | |
Argoproj Argo Cd | >=1.8.0<1.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-26924.
The severity of CVE-2021-26924 is medium.
The affected software is Argo CD versions 1.7.12 to 1.8.4.
The CWE ID for this vulnerability is CWE-79.
To fix this vulnerability, update Argo CD to version 1.8.4 or later.