Showing 1 vulnerability on this page for github.com/argoproj/argo-cd/v2/server

Signals CISA KEV Ransomware Nuclei
Go vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Unauthenticated Access to sensitive settings in Argo CD

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.

CWE-22CWE-287CWE-306CWE-384Jun 6, 20241 related artifact
CVSS5.3v3.1EPSS2.35%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX