CVE-2024-32476: Denial of Service via malicious jqPathExpressions in ignoreDifferences
Impact DoS vuln via OOM using jq in ignoreDifferences.
ignoreDifferences: - group: apps kind: Deployment jqPathExpressions: - 'until(true == false; [.] + [1])'
Patches A patch for this vulnerability has been released in the following Argo CD versions:
v2.10.8 v2.9.13 v2.8.17
For more information If you have any questions or comments about this advisory:
Open an issue in the Argo CD issue tracker or discussions Join us on Slack in channel #argo-cd
Credits This vulnerability was found & reported by @crenshaw-dev (Michael Crenshaw)
The Argo team would like to thank these contributors for their responsible disclosure and constructive communications during the resolve of this issue
Other sources
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. There is a Denial of Service (DoS) vulnerability via OOM using jq in ignoreDifferences. This vulnerability has been patched in version(s) 2.10.7, 2.9.12 and 2.8.16.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32476?
CVE-2024-32476 has been classified as a DoS vulnerability, allowing for potential outages due to out-of-memory conditions.
How do I fix CVE-2024-32476?
To fix CVE-2024-32476, update to Argo CD versions 2.8.17, 2.9.13, or 2.10.8 or later.
What software is affected by CVE-2024-32476?
CVE-2024-32476 affects specific versions of Argo CD between 2.1.0 and 2.10.0.
What impacts does CVE-2024-32476 have?
CVE-2024-32476 can cause denial of service by triggering out-of-memory conditions in the application.
Is there a patch available for CVE-2024-32476?
Yes, a patch has been released for CVE-2024-32476 in the latest versions of Argo CD.