Record summary

CVE-2024-37152 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 10, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE List>= 2.9.3, < 2.9.17affected
>= 2.10.0, < 2.10.12affected
>= 2.11.0, < 2.11.3affected

Default status: unknown

CVE List2.9.3 to < 2.9.17affected
2.10.0 to < 2.10.2affected
2.11.0 to < 2.11.3affected

github.com/argoproj/argo-cd/v2/server

Browse Go / github.com/argoproj/argo-cd/v2/server
GitHub Advisory2.9.3 to < 2.9.17 · Fixed in 2.9.17affected
2.10.0 to < 2.10.12 · Fixed in 2.10.12affected
2.11.0 to < 2.11.3 · Fixed in 2.11.3affected

Nuclei templates

1
ProjectDiscoveryMEDIUMArgo CD Unauthenticated Access to sensitive settingCVSS 7.5

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern.

Impact

Unauthenticated attackers can access sensitive password patterns and application settings exposed by the /api/v1/settings endpoint.

Remediation

Update Argo CD to a version that patches CVE-2024-37152.

WeaknessesCWE-306
AuthorsDhiyaneshDk
Template tagscvecve2024argo-cdinfo-leakvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*
Shodan: html:"Argo CD"

Source: ProjectDiscovery

References

5