We found results for “”
CVE-2024-36106
Good to know:
Date: June 6, 2024
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It’s possible for authenticated users to enumerate clusters by name by inspecting error messages. It’s also possible to enumerate the names of projects with project-scoped clusters if you know the names of the clusters. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.
Language: Go
Severity Score
Related Resources (5)
Severity Score
Weakness Type (CWE)
Generation of Error Message Containing Sensitive Information
CWE-209Top Fix
Upgrade Version
Upgrade to version github.com/argoproj/argo-cd - v2.9.17;github.com/argoproj/argo-cd - v2.10.12;github.com/argoproj/argo-cd - v2.11.3;github.com/argoproj/argo-cd/v2 - v2.9.17
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | NONE |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


