github.com
https://github.com/argoproj/argo-cd CVE-2024-32476
MEDIUM
Denial of Service via malicious jqPathExpressions in ignoreDifferences
Record summary
CVE-2024-32476 has a selected CVSS score of 6.5 (medium).
Description
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. There is a Denial of Service (DoS) vulnerability via OOM using jq in ignoreDifferences. This vulnerability has been patched in version(s) 2.10.7, 2.9.12 and 2.8.16.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 29, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
argo-cdBrowse argoproj / argo-cdDefault status: unknown | CVE List | 2.10.0 | affected |
| 2.9.0 | affected | ||
| * | affected | ||
| >= 2.10.0, < 2.10.8 | affected | ||
| >= 2.9.0, < 2.9.13 | affected | ||
| < 2.8.17 | affected | ||
github.com/argoproj/argo-cd/v2Browse Go / github.com/argoproj/argo-cd/v2 | GitHub Advisory | 2.10.0 to < 2.10.8 · Fixed in 2.10.8 | affected |
| 2.9.0 to < 2.9.13 · Fixed in 2.9.13 | affected | ||
| Before 2.8.17 · Fixed in 2.8.17 | affected |
References
6github.com
https://github.com/argoproj/argo-cd/commit/7893979a1e78d59cedd0ba790ded24e30bb40657 github.com
https://github.com/argoproj/argo-cd/commit/9e5cc5a26ff0920a01816231d59fdb5eae032b5a github.com
https://github.com/argoproj/argo-cd/commit/e2df7315fb7d96652186bf7435773a27be330cac github.comConfirmation
https://github.com/argoproj/argo-cd/security/advisories/GHSA-9m6p-x4h2-6frq nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-32476