Michael Crenshaw
9 exploits
Active since Jun 2022
Argo CD 0.11.0-2.1.16 - Insufficient Entropy in OAuth2/OIDC Login Flow Parameters
CVSS 8.3
Argo CD 1.0.0-2.1.16 - Stored Cross-Site Scripting via JavaScript Link Injection
CVSS 9.0
Argo CD 1.3.0-2.1.15 - Sensitive File Exposure via Symlink Following
CVSS 4.3
Argo CD <2.3.17, <2.4.23, <2.5.11, <2.6.2 - Privilege Escalation
CVSS 9.1
Argo CD 1.2.0-2.8.11, 2.9.0-2.9.7 - Improper Privilege Management via Local Sync Feature
CVSS 6.4
Argo CD 2.13.0-2.13.8 2.14.0-2.14.15 3.0.0-3.0.12 3.1.0-rc1-3.1.1 - Sensitive Info Exposure via API
CVSS 9.9
Argo CD 1.2.0-1.8.7, 2.0.0-rc1-2.14.19, 3.0.0-rc1-3.2.0-rc1, 3.1.7, 3.0.18 - DoS via Malformed Bitbucket Webhook
CVSS 7.5
Argo CD 1.2.0-1.8.7, 2.0.0-rc1-2.14.19, 3.0.0-rc1-3.2.0-rc1, 3.1.7, 3.0.18 - DoS via Gogs Webhook Push Event
CVSS 7.5
Argo CD <3.2.0-rc1 - Use After Free
CVSS 7.5