Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-43824

Опубликовано: 02 мая 2026
Источник: redhat
CVSS3: 9.6
EPSS Низкий

Описание

In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.

A flaw was found in Argo CD. The ServerSideDiff feature allows for the reading of cleartext Kubernetes Secret data. This vulnerability could lead to information disclosure, potentially exposing sensitive configuration details within the Kubernetes environment.

Отчет

This is an Important information disclosure flaw in Argo CD, as deployed in Red Hat OpenShift GitOps. The ServerSideDiff feature allows for the reading of cleartext Kubernetes Secret data, which could expose sensitive configuration details. This is considered Important due to the potential for unauthorized access to critical credentials and sensitive information within the Kubernetes environment. This vulnerability affects only applications which are deployed with the argocd.argoproj.io/compare-options: IncludeMutationWebhook=true annotation. To a successful attack take place the attacker requires only the accesses needed to successfully call the ServerSideDiff function and the secret the attacker is trying to exfiltrate needs to be owned by at least one non-ArgoCD SSA field manager, otherwise the value will be garbage collected and won't be present in the response. The Red Hat GitOps containers marked as not affected in the affects table doesn't ship the vulnerable ArgoCD version on, being older than the upstream version which introduced the vulnerability or the container is already updated to a patched version of ArgoCD.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Openshift Data Foundation 4odf4/odf-multicluster-rhel9-operatorNot affected
Red Hat OpenShift GitOpsopenshift-gitops-1/argocd-agent-rhel8Not affected
Red Hat OpenShift GitOpsopenshift-gitops-1/argocd-agent-rhel9Not affected
Red Hat OpenShift GitOpsopenshift-gitops-1/argocd-image-updater-rhel8Not affected
Red Hat OpenShift GitOpsopenshift-gitops-1/argocd-image-updater-rhel9Not affected
Red Hat OpenShift GitOpsopenshift-gitops-1/argocd-rhel8Not affected
Red Hat OpenShift GitOpsopenshift-gitops-1/argocd-rhel9Not affected
Red Hat OpenShift GitOpsopenshift-gitops-1/gitops-rhel8Not affected
Red Hat OpenShift GitOpsopenshift-gitops-1/gitops-rhel8-operatorNot affected
Red Hat OpenShift GitOpsopenshift-gitops-1/gitops-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-312
https://bugzilla.redhat.com/show_bug.cgi?id=2464613github.com/argoproj/argo-cd/: Argo CD: Information disclosure via ServerSideDiff allows reading Kubernetes Secret data

EPSS

Процентиль: 13%
0.00225
Низкий

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 7.7
nvd
3 месяца назад

In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.

CVSS3: 7.7
github
3 месяца назад

In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.

EPSS

Процентиль: 13%
0.00225
Низкий

9.6 Critical

CVSS3