Record summary

CVE-2024-32476 has a selected CVSS score of 6.5 (medium).

Description

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. There is a Denial of Service (DoS) vulnerability via OOM using jq in ignoreDifferences. This vulnerability has been patched in version(s) 2.10.7, 2.9.12 and 2.8.16.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 29, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unknown

CVE List2.10.0affected
2.9.0affected
*affected
>= 2.10.0, < 2.10.8affected
>= 2.9.0, < 2.9.13affected
< 2.8.17affected

github.com/argoproj/argo-cd/v2

Browse Go / github.com/argoproj/argo-cd/v2
GitHub Advisory2.10.0 to < 2.10.8 · Fixed in 2.10.8affected
2.9.0 to < 2.9.13 · Fixed in 2.9.13affected
Before 2.8.17 · Fixed in 2.8.17affected

References

6