Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-37152

Опубликовано: 06 июн. 2024
Источник: redhat
CVSS3: 5.3

Описание

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.

A flaw was found in Argo-CD. There is an issue with unauthenticated information disclosure of settings data through an exposed API endpoint at /api/v1/settings.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Openshift Data Foundation 4odf4/odr-rhel9-operatorNot affected
Red Hat OpenShift GitOpsopenshift-gitops-1/argocd-rhel8Will not fix
Red Hat OpenShift GitOpsopenshift-gitops-1/argocd-rhel9Will not fix
Red Hat OpenShift GitOpsopenshift-gitops-1/gitops-operator-bundleWill not fix
Red Hat OpenShift GitOpsopenshift-gitops-1/gitops-rhel8Will not fix
Red Hat OpenShift GitOpsopenshift-gitops-1/gitops-rhel8-operatorWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2292313argo-cd: Unauthenticated information disclosure in /api/v1/settings endpoint

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
около 2 лет назад

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.

CVSS3: 5.3
github
около 2 лет назад

Unauthenticated Access to sensitive settings in Argo CD

CVSS3: 5.3
fstec
около 2 лет назад

Уязвимость декларативного инструмента непрерывной доставки GitOps для Kubernetes Argo CD, связанная с недостатками процедуры аутентификации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

5.3 Medium

CVSS3