CVE-2021-26924: XSS
Published Mar 15, 2021
·Updated
An issue was discovered in Argo CD before 1.8.4. Browser XSS protection is not activated due to the missing XSS protection header.
Affected Software
4 affected components
argoproj Argo CD<1.7.12
argoproj Argo CD>=1.8.0<1.8.4
linuxfoundation Argo-cd<1.7.12
linuxfoundation Argo-cd>=1.8.0<1.8.4
Remediation
Patch Available
Event History
Mar 15, 2021
CVE Published
via MITRE·02:42 PM
Data Sourced
via MITRE·02:42 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-26924.
2
What is the severity of CVE-2021-26924?
The severity of CVE-2021-26924 is medium.
3
What is the affected software?
The affected software is Argo CD versions 1.7.12 to 1.8.4.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-79.
5
How can I fix this vulnerability?
To fix this vulnerability, update Argo CD to version 1.8.4 or later.