CVE-2021-3557: Medium severity argo cd vulnerability
A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-server, the unprivileged user is able to read all resources of the cluster including all secrets which might enable privilege escalations. The highest threat from this vulnerability is to data confidentiality.
Other sources
Any unprivileged user is able to deploy argocd in his namespace and with the created ServiceAccount argocd-argocd-server, the unprivileged user is able to read all resources of the cluster like all secrets which might enable privilege escalations.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw in argocd?
The vulnerability ID for this flaw in argocd is CVE-2021-3557.
What is the severity of CVE-2021-3557?
The severity of CVE-2021-3557 is medium.
How does CVE-2021-3557 affect argocd?
CVE-2021-3557 allows any unprivileged user to deploy argocd in their namespace and read all resources of the cluster, including secrets, potentially enabling privilege escalations.
Which software versions are affected by CVE-2021-3557?
The affected software versions are Argo CD up to version 1.1.1 and Red Hat OpenShift GitOps version 1.1.
How can I fix CVE-2021-3557?
To fix CVE-2021-3557, update Argo CD to version 1.1.2 or later.