Описание
In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.
A flaw was found in Argo CD. The ServerSideDiff feature allows for the reading of cleartext Kubernetes Secret data. This vulnerability could lead to information disclosure, potentially exposing sensitive configuration details within the Kubernetes environment.
Отчет
This is an Important information disclosure flaw in Argo CD, as deployed in Red Hat OpenShift GitOps. The ServerSideDiff feature allows for the reading of cleartext Kubernetes Secret data, which could expose sensitive configuration details. This is considered Important due to the potential for unauthorized access to critical credentials and sensitive information within the Kubernetes environment.
This vulnerability affects only applications which are deployed with the argocd.argoproj.io/compare-options: IncludeMutationWebhook=true annotation. To a successful attack take place the attacker requires only the accesses needed to successfully call the ServerSideDiff function and the secret the attacker is trying to exfiltrate needs to be owned by at least one non-ArgoCD SSA field manager, otherwise the value will be garbage collected and won't be present in the response.
The Red Hat GitOps containers marked as not affected in the affects table doesn't ship the vulnerable ArgoCD version on, being older than the upstream version which introduced the vulnerability or the container is already updated to a patched version of ArgoCD.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Openshift Data Foundation 4 | odf4/odf-multicluster-rhel9-operator | Not affected | ||
| Red Hat OpenShift GitOps | openshift-gitops-1/argocd-agent-rhel8 | Not affected | ||
| Red Hat OpenShift GitOps | openshift-gitops-1/argocd-agent-rhel9 | Not affected | ||
| Red Hat OpenShift GitOps | openshift-gitops-1/argocd-image-updater-rhel8 | Not affected | ||
| Red Hat OpenShift GitOps | openshift-gitops-1/argocd-image-updater-rhel9 | Not affected | ||
| Red Hat OpenShift GitOps | openshift-gitops-1/argocd-rhel8 | Not affected | ||
| Red Hat OpenShift GitOps | openshift-gitops-1/argocd-rhel9 | Not affected | ||
| Red Hat OpenShift GitOps | openshift-gitops-1/gitops-rhel8 | Not affected | ||
| Red Hat OpenShift GitOps | openshift-gitops-1/gitops-rhel8-operator | Not affected | ||
| Red Hat OpenShift GitOps | openshift-gitops-1/gitops-rhel9 | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
9.6 Critical
CVSS3
Связанные уязвимости
In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.
In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.
EPSS
9.6 Critical
CVSS3