Description

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability in Argo CD, where an unauthenticated attacker can send a specially crafted large JSON payload to the /api/webhook endpoint, causing excessive memory allocation that leads to service disruption by triggering an Out Of Memory (OOM) kill. The issue poses a high risk to the availability of Argo CD deployments. This vulnerability is fixed in 2.11.6, 2.10.15, and 2.9.20.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 23, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Default status: unknown

CVE List1.0.0 to < 2.9.20affected
2.10.0 to < 2.10.15affected
2.11.0 to < 2.11.6affected
>= 1.0.0, < 2.9.20affected
>= 2.10.0, < 2.10.15affected
>= 2.11.0, < 2.11.6affected

github.com/argoproj/argo-cd

Browse Go / github.com/argoproj/argo-cd
GitHub Advisory1.0.0 to ≤ 1.8.7affected

github.com/argoproj/argo-cd/v2

Browse Go / github.com/argoproj/argo-cd/v2
GitHub AdvisoryBefore 2.9.20 · Fixed in 2.9.20affected
2.10.0 to < 2.10.15 · Fixed in 2.10.15affected
2.11.0 to < 2.11.6 · Fixed in 2.11.6affected

References

7