Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository. The vulnerability assumes the user has write access to the repository and can exploit it, either intentionally or unintentionally, by committing an invalid Secret to repository and triggering a Sync. Once exploited, any user with read access to Argo CD can view the exposed secret data. The vulnerability is fixed in v2.13.4, v2.12.10, and v2.11.13.
End of life: 8/5/2024, Latest version: 2.9.22
End of life: 8/5/2024, Latest version: 2.9.22
End of life: 5/7/2024, Latest version: 2.8.21
End of life: 5/7/2024, Latest version: 2.8.21
End of life: 2/5/2024, Latest version: 2.7.18
End of life: 2/5/2024, Latest version: 2.7.18
Security Fix(es): goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be (CVE-2021-4238) go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents (CVE-2022-3064) ArgoCD: Users with any cluster secret update access may update out-of-bounds cluster secrets (CVE-2023-23947) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es): goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be (CVE-2021-4238) go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents (CVE-2022-3064) ArgoCD: Users with any cluster secret update access may update out-of-bounds cluster secrets (CVE-2023-23947) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es): goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be (CVE-2021-4238) go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents (CVE-2022-3064) ArgoCD: Users with any cluster secret update access may update out-of-bounds cluster secrets (CVE-2023-23947) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
End of life: 11/5/2023, Latest version: 2.6.15
End of life: 11/5/2023, Latest version: 2.6.15
End of life: 8/7/2023, Latest version: 2.5.22
End of life: 8/7/2023, Latest version: 2.5.22
End of life: 5/2/2023, Latest version: 2.4.28
End of life: 5/2/2023, Latest version: 2.4.28
End of life: 2/7/2023, Latest version: 2.3.17
End of life: 2/7/2023, Latest version: 2.3.17
End of life: 10/26/2022, Latest version: 2.2.16
End of life: 10/26/2022, Latest version: 2.2.16
End of life: 6/11/2022, Latest version: 2.1.16
End of life: 6/11/2022, Latest version: 2.1.16
End of life: 3/6/2022, Latest version: 2.0.5
End of life: 3/6/2022, Latest version: 2.0.5
End of life: 12/15/2021, Latest version: 1.8.7
End of life: 12/15/2021, Latest version: 1.8.7
End of life: 8/20/2021, Latest version: 1.7.14
End of life: 8/20/2021, Latest version: 1.7.14
End of life: 12/15/2021, Latest version: 1.6.2
End of life: 12/15/2021, Latest version: 1.6.2