REDHAT-BUG-2467882: High severity Argo CD Argo CD vulnerability
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism. This issue has been patched in versions 3.2.11 and 3.3.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
argoproj/argo-cdto a version that resolves this vulnerability.Fixed in 3.2.11 - Upgrade
Upgrade
argoproj/argo-cdto a version that resolves this vulnerability.Fixed in 3.3.9