REDHAT-BUG-2467882: High severity Argo CD Argo CD vulnerability
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism. This issue has been patched in versions 3.2.11 and 3.3.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
argoproj/argo-cdto a version that resolves this vulnerability.Fixed in 3.2.11 - Upgrade
Upgrade
argoproj/argo-cdto a version that resolves this vulnerability.Fixed in 3.3.9
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2467882?
The severity of REDHAT-BUG-2467882 is classified as high, with a score of 7.
How do I fix REDHAT-BUG-2467882?
To remediate REDHAT-BUG-2467882, upgrade Argo CD to version 3.2.11 or later for the 3.2.x series, and to version 3.3.9 or later for the 3.3.x series.
What versions of Argo CD are affected by REDHAT-BUG-2467882?
REDHAT-BUG-2467882 affects Argo CD versions from 3.2.0 to before 3.2.11 and from 3.3.0 to before 3.3.9.
What type of vulnerability is REDHAT-BUG-2467882?
REDHAT-BUG-2467882 is classified as a missing authorization and data-masking vulnerability within the ServerSideDiff endpoint of Argo CD.
What kind of access is required for exploitation of REDHAT-BUG-2467882?
An attacker with read-only access can exploit REDHAT-BUG-2467882 to extract plaintext Kubernetes secrets.