pasha-codefresh
21 exploits
Active since Aug 2023
Argo CD < 2.8.13, 2.9.9, 2.10.4 - Brute Force Protection Bypass via Cache Overflow
CVSS 7.5
Argo CD < 2.8.13, 2.9.9, 2.10.4 - Brute Force Protection Bypass via Cache Overflow
CVSS 7.5
Argo CD 2.4.0-2.8.13 - Denial of Service via Malicious Helm Registry
CVSS 6.5
Argo CD <2.10.7-2.8.16 - Privilege Escalation
CVSS 4.8
Argo CD 2.1.0-2.8.16, 2.10.0-2.10.7 - Denial of Service via jq in ignoreDifferences
CVSS 6.5
Argo CD < 2.9.20 - Unauthenticated Denial of Service via Large JSON Payload to Webhook Endpoint
CVSS 7.5
Argo CD 2.4.0-2.8.13 - Denial of Service via Malicious Helm Registry
CVSS 6.5
Argo CD <2.10.7-2.8.16 - Privilege Escalation
CVSS 4.8
Argo CD 2.1.0-2.8.16, 2.10.0-2.10.7 - Denial of Service via jq in ignoreDifferences
CVSS 6.5
Argo CD < 2.9.20 - Unauthenticated Denial of Service via Large JSON Payload to Webhook Endpoint
CVSS 7.5
Argo CD 2.6.0-2.9.21 - Privilege Escalation via Web Terminal Permission Revocation Bypass
CVSS 4.7
Argo CD 2.6.0-2.9.21 - Privilege Escalation via Web Terminal Permission Revocation Bypass
CVSS 4.7
Argo CD 2.6.0-2.6.13 - Insufficient Session Expiration in Web Terminal
CVSS 4.7
Argo CD 2.4.0-2.6.14 - Denial of Service via Malicious tar.gz File Extraction
CVSS 6.5
Argo CD < 2.8.13, 2.9.9, 2.10.4 - Brute Force Protection Bypass via Cache Overflow
CVSS 7.5
Argo CD 2.4.0-2.8.13 - Denial of Service via Malicious Helm Registry
CVSS 6.5
Argo CD <2.10.7-2.8.16 - Privilege Escalation
CVSS 4.8
Argo CD 2.1.0-2.8.16, 2.10.0-2.10.7 - Denial of Service via jq in ignoreDifferences
CVSS 6.5
Argo CD <2.11.3-2.9.17 - Info Disclosure
CVSS 4.3
Argo CD < 2.9.20 - Unauthenticated Denial of Service via Large JSON Payload to Webhook Endpoint
CVSS 7.5
Argo CD 2.6.0-2.9.21 - Privilege Escalation via Web Terminal Permission Revocation Bypass
CVSS 4.7