github.com
https://github.com/argoproj/argo-cd CVE-2024-40634
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint
Description
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability in Argo CD, where an unauthenticated attacker can send a specially crafted large JSON payload to the /api/webhook endpoint, causing excessive memory allocation that leads to service disruption by triggering an Out Of Memory (OOM) kill. The issue poses a high risk to the availability of Argo CD deployments. This vulnerability is fixed in 2.11.6, 2.10.15, and 2.9.20.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 23, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
argo-cdBrowse argoproj / argo-cdDefault status: unknown | CVE List | 1.0.0 to < 2.9.20 | affected |
| 2.10.0 to < 2.10.15 | affected | ||
| 2.11.0 to < 2.11.6 | affected | ||
| >= 1.0.0, < 2.9.20 | affected | ||
| >= 2.10.0, < 2.10.15 | affected | ||
| >= 2.11.0, < 2.11.6 | affected | ||
github.com/argoproj/argo-cdBrowse Go / github.com/argoproj/argo-cd | GitHub Advisory | 1.0.0 to ≤ 1.8.7 | affected |
github.com/argoproj/argo-cd/v2Browse Go / github.com/argoproj/argo-cd/v2 | GitHub Advisory | Before 2.9.20 · Fixed in 2.9.20 | affected |
| 2.10.0 to < 2.10.15 · Fixed in 2.10.15 | affected | ||
| 2.11.0 to < 2.11.6 · Fixed in 2.11.6 | affected |
References
7github.com
https://github.com/argoproj/argo-cd/commit/46c0c0b64deaab1ece70cb701030b76668ad0cdc github.com
https://github.com/argoproj/argo-cd/commit/540e3a57b90eb3655db54793332fac86bcc38b36 github.com
https://github.com/argoproj/argo-cd/commit/d881ee78949e23160a0b280bb159e4d3d625a4df github.comConfirmation
https://github.com/argoproj/argo-cd/security/advisories/GHSA-jmvp-698c-4x3w nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-40634 pkg.go.dev
https://pkg.go.dev/vuln/GO-2024-3002