CVE-2024-36106

MEDIUM

Argo CD <2.11.3-2.9.17 - Info Disclosure

Title source: llm
STIX 2.1

Description

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It’s possible for authenticated users to enumerate clusters by name by inspecting error messages. It’s also possible to enumerate the names of projects with project-scoped clusters if you know the names of the clusters. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.

Scores

CVSS v3 4.3
EPSS 0.0064
EPSS Percentile 70.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-209
Status published
Products (2)
argoproj/argo-cd 0.11.0 - 2.9.17Go
argoproj/argo_cd 0.11.0 - 2.9.17
Published Jun 06, 2024
Tracked Since Feb 18, 2026