CVE-2024-32476

MEDIUM

Argo CD 2.1.0-2.8.16, 2.10.0-2.10.7 - Denial of Service via jq in ignoreDifferences

Title source: llm
STIX 2.1

Description

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. There is a Denial of Service (DoS) vulnerability via OOM using jq in ignoreDifferences. This vulnerability has been patched in version(s) 2.10.7, 2.9.12 and 2.8.16.

Scores

CVSS v3 6.5
EPSS 0.0100
EPSS Percentile 58.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (2)
argoproj/argo-cd 2.10.0 - 2.10.8Go
argoproj/argo_cd 2.1.0 - 2.8.17
Published May 14, 2024
Tracked Since Feb 18, 2026