Описание
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism. This issue has been patched in versions 3.2.11 and 3.3.9.
A flaw was found in Argo CD, a GitOps continuous delivery tool for Kubernetes. A missing authorization and data-masking gap in the ServerSideDiff endpoint allows an attacker with read-only access to extract sensitive Kubernetes Secret data. This information disclosure occurs by leveraging the Kubernetes API server's Server-Side Apply dry-run mechanism, potentially exposing critical configuration and credentials.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Openshift Data Foundation 4 | odf4/odf-multicluster-rhel9-operator | Affected | ||
| Red Hat OpenShift GitOps | openshift-gitops-1/argocd-agent-rhel8 | Not affected | ||
| Red Hat OpenShift GitOps | openshift-gitops-1/argocd-rhel8 | Not affected | ||
| Red Hat OpenShift GitOps | openshift-gitops-1/gitops-rhel8 | Not affected | ||
| Red Hat OpenShift GitOps | openshift-gitops-1/gitops-rhel8-operator | Not affected | ||
| Red Hat OpenShift GitOps | openshift-gitops-1/gitops-rhel9 | Not affected | ||
| Red Hat OpenShift GitOps 1.19 | openshift-gitops-1/argocd-image-updater-rhel8 | Fixed | RHSA-2026:20943 | 26.05.2026 |
| Red Hat OpenShift GitOps 1.20 | openshift-gitops-1/argocd-rhel9 | Fixed | RHBA-2026:12433 | 30.04.2026 |
| Red Hat OpenShift GitOps 1.20 | openshift-gitops-1/argocd-agent-rhel9 | Fixed | RHSA-2026:20947 | 26.05.2026 |
| Red Hat OpenShift GitOps 1.20 | openshift-gitops-1/argocd-image-updater-rhel9 | Fixed | RHSA-2026:20947 | 26.05.2026 |
Показывать по
Дополнительная информация
Статус:
7.7 High
CVSS3
Связанные уязвимости
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism. This issue has been patched in versions 3.2.11 and 3.3.9.
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
Уязвимость декларативного инструмента непрерывной доставки GitOps для Kubernetes Argo CD, связанная с неправильным межграничным удалением критичных данных, позволяющая нарушителю раскрыть защищаемую информацию
7.7 High
CVSS3