linuxfoundation Vulnerabilities and Affected Products
Vulnerabilities associated with argo-cd.
Products
Clear product- yocto8 vulnerabilities
- edge_virtualization_engine3 vulnerabilities
- zowe_api_mediation_layer3 vulnerabilities
- argo-cd2 vulnerabilities
- onnx2 vulnerabilities
- cortex1 vulnerability
- fluid1 vulnerability
- opendaylight1 vulnerability
- runc1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-37152MEDIUM | Unauthenticated Access to sensitive settings in Argo CDArgo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17. | CVSS5.3v3.1 | EPSS2.35% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-21662HIGH | Argo CD vulnerable to Bypassing of Rate Limit and Brute Force Protection Using Cache OverflowArgo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can effectively bypass the rate limit and brute force protections by exploiting the application's weak cache-based mechanism. This loophole in security can be combined with other vulnerabilities to attack the default admin account. This flaw undermines a patch for CVE-2020-8827 intended to protect against brute-force attacks. The application's brute force protection … CWE-307Mar 18, 2024 | CVSS7.5v3.1 | EPSS0.838% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |