Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-22424

Опубликовано: 19 янв. 2024
Источник: nvd
CVSS3: 8.3
EPSS Низкий

Описание

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.15 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which contains code to call Argo CD API endpoints on the victim’s behalf. For example, an attacker could send an Argo CD user a link to a page which looks harmless but in the background calls an Argo CD API endpoint to create an application running malicious code. Argo CD uses the “Lax” SameSite cookie policy to prevent CSRF attacks where the attacker controls an external domain. The malicious external website can attempt to call the Argo CD API, but the web browser will refuse to send the Argo CD auth token with the request. Many companies host Argo CD on an internal subdomain. If an attacker can p

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*
Версия от 2.8.0 (включая) до 2.8.8 (исключая)
cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*
Версия от 2.9.0 (включая) до 2.9.4 (исключая)
cpe:2.3:a:argoproj:argo_cd:2.10.0:rc1:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:argo-cd:*:*:*:*:*:*:*:*
Версия от 0.1.0 (включая) до 2.7.16 (исключая)

EPSS

Процентиль: 20%
0.00064
Низкий

8.3 High

CVSS3

Дефекты

CWE-352
CWE-352

Связанные уязвимости

CVSS3: 8.3
redhat
около 2 лет назад

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.15 are vulnerable to a cross-server request forgery (CSRF) attack when the attacker has the ability to write HTML to a page on the same parent domain as Argo CD. A CSRF attack works by tricking an authenticated Argo CD user into loading a web page which contains code to call Argo CD API endpoints on the victim’s behalf. For example, an attacker could send an Argo CD user a link to a page which looks harmless but in the background calls an Argo CD API endpoint to create an application running malicious code. Argo CD uses the “Lax” SameSite cookie policy to prevent CSRF attacks where the attacker controls an external domain. The malicious external website can attempt to call the Argo CD API, but the web browser will refuse to send the Argo CD auth token with the request. Many companies host Argo CD on an internal subdomain. If an attacker ca...

CVSS3: 8.3
github
около 2 лет назад

github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability

CVSS3: 8.3
fstec
около 2 лет назад

Уязвимость интерфейса декларативного инструмента непрерывной доставки GitOps для Kubernetes Argo CD, позволяющая нарушителю обойти ограничения безопасности и осуществить CSRF-атаку

EPSS

Процентиль: 20%
0.00064
Низкий

8.3 High

CVSS3

Дефекты

CWE-352
CWE-352