REDHAT-BUG-2496732: High severity Argo Argo CD repo-server vulnerability
An unauthenticated attacker can exploit the Argo CD repo-server's GenerateManifest gRPC endpoint by supplying malicious KustomizeOptions (specifically BuildOptions or BinaryPath), causing arbitrary commands to be executed in the repo-server pod. When combined with Redis cache manipulation, this can result in the deployment of attacker-controlled Kubernetes manifests, potentially leading to complete compromise of the Kubernetes cluster.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2496732?
The severity of REDHAT-BUG-2496732 is classified as high with a score of 7.
How can I fix REDHAT-BUG-2496732?
To fix REDHAT-BUG-2496732, update the Argo CD repo-server to the latest patched version provided by Red Hat.
What impact does REDHAT-BUG-2496732 have on my system?
REDHAT-BUG-2496732 allows an unauthenticated attacker to execute arbitrary commands on the repo-server pod.
What is the nature of the vulnerability in REDHAT-BUG-2496732?
REDHAT-BUG-2496732 involves exploiting the GenerateManifest gRPC endpoint by providing malicious KustomizeOptions.
Are there any workarounds for REDHAT-BUG-2496732 before applying the fix?
Currently, no specific workarounds are recommended for REDHAT-BUG-2496732, so upgrading is advised as the best precaution.