CVE-2022-31035

CRITICAL

Argo CD <v1.0.0 - XSS

Title source: llm
STIX 2.1

Description

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.0.0 are vulnerable to a cross-site scripting (XSS) bug allowing a malicious user to inject a `javascript:` link in the UI. When clicked by a victim user, the script will execute with the victim's permissions (up to and including admin). The script would be capable of doing anything which is possible in the UI or via the API, such as creating, modifying, and deleting Kubernetes resources. A patch for this vulnerability has been released in the following Argo CD versions: v2.4.1, v2.3.5, v2.2.10 and v2.1.16. There are no completely-safe workarounds besides upgrading.

References (3)

Core 3

Scores

CVSS v3 9.0
EPSS 0.0077
EPSS Percentile 73.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (6)
argoproj/argo-cd 0 - 2.1.16Go
argoproj/argo-cd 1.0.0 - 2.1.16Go
argoproj/argo_cd 2.2.9
argoproj/argo_cd 2.3.4
argoproj/argo_cd 2.4.0
argoproj/argo_cd 1.0.0 - 2.1.16
Published Jun 27, 2022
Tracked Since Feb 18, 2026