Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42880

Опубликовано: 07 мая 2026
Источник: redhat
CVSS3: 7.7

Описание

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism. This issue has been patched in versions 3.2.11 and 3.3.9.

A flaw was found in Argo CD, a GitOps continuous delivery tool for Kubernetes. A missing authorization and data-masking gap in the ServerSideDiff endpoint allows an attacker with read-only access to extract sensitive Kubernetes Secret data. This information disclosure occurs by leveraging the Kubernetes API server's Server-Side Apply dry-run mechanism, potentially exposing critical configuration and credentials.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Openshift Data Foundation 4odf4/odf-multicluster-rhel9-operatorAffected
Red Hat OpenShift GitOpsopenshift-gitops-1/argocd-agent-rhel8Not affected
Red Hat OpenShift GitOpsopenshift-gitops-1/argocd-rhel8Not affected
Red Hat OpenShift GitOpsopenshift-gitops-1/gitops-rhel8Not affected
Red Hat OpenShift GitOpsopenshift-gitops-1/gitops-rhel8-operatorNot affected
Red Hat OpenShift GitOpsopenshift-gitops-1/gitops-rhel9Not affected
Red Hat OpenShift GitOps 1.19openshift-gitops-1/argocd-image-updater-rhel8FixedRHSA-2026:2094326.05.2026
Red Hat OpenShift GitOps 1.20openshift-gitops-1/argocd-rhel9FixedRHBA-2026:1243330.04.2026
Red Hat OpenShift GitOps 1.20openshift-gitops-1/argocd-agent-rhel9FixedRHSA-2026:2094726.05.2026
Red Hat OpenShift GitOps 1.20openshift-gitops-1/argocd-image-updater-rhel9FixedRHSA-2026:2094726.05.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=2467882argoproj/argo-cd: Argo CD: Information disclosure of Kubernetes Secret data via Server-Side Apply dry-run mechanism

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 9.6
nvd
3 месяца назад

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism. This issue has been patched in versions 3.2.11 and 3.3.9.

CVSS3: 9.6
github
3 месяца назад

ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction

CVSS3: 9.6
fstec
3 месяца назад

Уязвимость декларативного инструмента непрерывной доставки GitOps для Kubernetes Argo CD, связанная с неправильным межграничным удалением критичных данных, позволяющая нарушителю раскрыть защищаемую информацию

7.7 High

CVSS3