Record summary

CVE-2022-31016 has a selected CVSS score of 6.5 (medium).

Description

Argo CD is a declarative continuous deployment for Kubernetes. Argo CD versions v0.7.0 and later are vulnerable to an uncontrolled memory consumption bug, allowing an authorized malicious user to crash the repo-server service, resulting in a Denial of Service. The attacker must be an authenticated Argo CD user authorized to deploy Applications from a repository which contains (or can be made to contain) a large file. The fix for this vulnerability is available in versions 2.3.5, 2.2.10, 2.1.16, and later. There are no known workarounds. Users are recommended to upgrade.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE List>= 0.7.0, < 2.1.16affected
> 2.0.0, < 2.2.10affected
> 2.3.0, < 2.3.5affected

github.com/argoproj/argo-cd

Browse Go / github.com/argoproj/argo-cd
GitHub Advisory0.7.0 to < 2.1.16 · Fixed in 2.1.16affected

github.com/argoproj/argo-cd/v2

Browse Go / github.com/argoproj/argo-cd/v2
GitHub AdvisoryBefore 2.1.16 · Fixed in 2.1.16affected
2.2.0 to < 2.2.10 · Fixed in 2.2.10affected
2.3.0 to < 2.3.5 · Fixed in 2.3.5affected
2.4.0affected
2.4.0 to < 2.4.1 · Fixed in 2.4.1affected

References

3