CVE-2023-40029: Cluster secret might leak in cluster details page in Argo CD

Published Aug 21, 2023
·
Updated

Impact

Argo CD Cluster secrets might be managed declaratively using Argo CD / kubectl apply. As a result, the full secret body is stored inkubectl.kubernetes.io/last-applied-configuration annotation.

https://github.com/argoproj/argo-cd/pull/7139 introduced the ability to manage cluster labels and annotations. Since clusters are stored as secrets it also exposes the kubectl.kubernetes.io/last-applied-configuration annotation which includes full secret body. In order to view the cluster annotations via the Argo CD API, the user must have clusters, get RBAC access.

Note: In many cases, cluster secrets do not contain any actually-secret information. But sometimes, as in bearer-token auth, the contents might be very sensitive.

Patches

The bug has been patched in the following versions:

2.8.3 2.7.14 2.6.15

Workarounds

Update/Deploy cluster secret with server-side-apply flag which does not use or rely on kubectl.kubernetes.io/last-applied-configuration annotation. Note: annotation for existing secrets will require manual removal.

For more information

Open an issue in the Argo CD issue tracker or discussions Join us on Slack in channel #argo-cd

Other sources

Argo CD Cluster secrets might be managed declaratively using Argo CD/kubectl apply. As a result, the full secret body is stored inkubectl.kubernetes.io/last-applied-configuration annotation. https://github.com/argoproj/argo-cd/pull/7139 introduced the ability to manage cluster labels and annotations. Since clusters are stored as secrets it also exposes the kubectl.kubernetes.io/last-applied-configuration annotation which includes full secret body. In order to view the cluster annotations via the Argo CD API, the user must have clusters, get RBAC access.

Note: In many cases, cluster secrets do not contain any actually-secret information. But sometimes, as in bearer-token auth, the contents might be very sensitive.

Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively using Argo CD / kubectl apply. As a result, the full secret body is stored inkubectl.kubernetes.io/last-applied-configuration annotation. pull request #7139 introduced the ability to manage cluster labels and annotations. Since clusters are stored as secrets it also exposes the kubectl.kubernetes.io/last-applied-configuration annotation which includes full secret body. In order to view the cluster annotations via the Argo CD API, the user must have clusters, get RBAC access. Note: In many cases, cluster secrets do not contain any actually-secret information. But sometimes, as in bearer-token auth, the contents might be very sensitive. The bug has been patched in versions 2.8.3, 2.7.14, and 2.6.15. Users are advised to upgrade. Users unable to upgrade should update/deploy cluster secret with server-side-apply flag which does not use or rely on kubectl.kubernetes.io/last-applied-configuration annotation. Note: annotation for existing secrets will require manual removal.

MITRE

Affected Software

12 affected componentsFixes available
go/github.com/argoproj/argo-cd/v2>=2.8.0<2.8.3
2.8.3
go/github.com/argoproj/argo-cd/v2>=2.7.0<2.7.14
2.7.14
go/github.com/argoproj/argo-cd/v2>=2.2.0<2.6.15
2.6.15
redhat/ArgoCD<2.8.1
2.8.1
redhat/ArgoCD<2.7.12
2.7.12
redhat/ArgoCD<2.6.14
2.6.14
argoproj Argo CD>=2.2.0<2.6.15
argoproj Argo CD>=2.7.0<2.7.14
argoproj Argo CD>=2.8.0<2.8.3
linuxfoundation Argo Continuous Delivery Kubernetes>=2.2.0<2.6.15
linuxfoundation Argo Continuous Delivery Kubernetes>=2.7.0<2.7.14
linuxfoundation Argo Continuous Delivery Kubernetes>=2.8.0<2.8.3

Event History

Sep 7, 2023
CVE Published
via MITRE·10:11 PM
Data Sourced
via MITRE·10:11 PM
DescriptionSeverityWeakness
Sep 11, 2023
Advisory Published
12:59 PM

Frequently Asked Questions

1

What is CVE-2023-40029?

CVE-2023-40029 is a vulnerability in Argo CD where cluster secrets might be managed declaratively.

2

What is the impact of CVE-2023-40029?

The impact of CVE-2023-40029 is that the full secret body is stored in a specific annotation.

3

How severe is CVE-2023-40029?

CVE-2023-40029 has a severity rating of 9.9 (Critical).

4

Which versions of Argo CD are affected by CVE-2023-40029?

Argo CD versions up to and excluding 2.8.1 are affected by CVE-2023-40029.

5

How can I fix CVE-2023-40029?

To fix CVE-2023-40029, update Argo CD to version 2.8.1 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203